CVE-2021-44487: Null Pointer Dereference
Published Apr 15, 2022
·Updated
An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack of NULL checks in calls to iousopen in srunix/iousopen.c allows attackers to crash the application by dereferencing a NULL pointer.
Affected Software
2 affected components
Fisglobal Gt.m<=7.0-000
YottaDB YottaDB<=1.32
Event History
Apr 15, 2022
CVE Published
via MITRE·05:22 PM
Data Sourced
via MITRE·05:22 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue in YottaDB?
The vulnerability ID for this issue in YottaDB is CVE-2021-44487.
2
What is the severity of CVE-2021-44487?
The severity of CVE-2021-44487 is high with a CVSS score of 7.5.
3
What software versions are affected by CVE-2021-44487?
Fisglobal Gt.m versions up to and including 7.0-000 and Yottadb versions up to and including 1.32 are affected by CVE-2021-44487.
4
What is the impact of CVE-2021-44487?
CVE-2021-44487 allows attackers to crash the application by dereferencing a NULL pointer.
5
Is there a fix available for CVE-2021-44487?
At the time of writing, there is no known fix or patch available for CVE-2021-44487. It is recommended to apply any future updates or patches provided by the vendor.