CVE-2021-44485: Null Pointer Dereference
Published Apr 15, 2022
·Updated
An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack of NULL checks in tripgen in srport/emitcode.c allows attackers to crash the application by dereferencing a NULL pointer.
Affected Software
2 affected components
Fisglobal Gt.m<=7.0-000
YottaDB YottaDB<=1.32
Event History
Apr 15, 2022
CVE Published
via MITRE·05:21 PM
Data Sourced
via MITRE·05:21 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-44485?
The severity of CVE-2021-44485 is high with a CVSS score of 7.5.
2
What is the affected software for CVE-2021-44485?
The affected software for CVE-2021-44485 includes Fisglobal Gt.m versions up to 7.0-000 and Yottadb Yottadb versions up to 1.32.
3
How can attackers exploit CVE-2021-44485?
Attackers can exploit CVE-2021-44485 by crashing the application through the dereferencing of a NULL pointer.
4
Is there a fix available for CVE-2021-44485?
At the time of writing, there is no fix available for CVE-2021-44485. It is recommended to monitor official sources for updates.
5
Where can I find more information about CVE-2021-44485?
You can find more information about CVE-2021-44485 on the GitLab page: https://gitlab.com/YottaDB/DB/YDB/-/issues/828