CVE-2021-44488: Critical severity yottadb vulnerability
Published Apr 15, 2022
·Updated
An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can control the size and input to calls to memcpy in opfnfnumber in srport/opfnfnumber.c in order to corrupt memory or crash the application.
Affected Software
2 affected components
Fisglobal Gt.m<=7.0-000
YottaDB YottaDB<=1.32
Event History
Apr 15, 2022
CVE Published
via MITRE·05:23 PM
Data Sourced
via MITRE·05:23 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-44488.
2
What is the severity of CVE-2021-44488?
The severity of CVE-2021-44488 is critical with a CVSS score of 9.1.
3
Which software is affected by CVE-2021-44488?
Fisglobal Gt.m versions up to 7.0-000 and Yottadb versions up to 1.32 are affected by CVE-2021-44488.
4
How can an attacker exploit CVE-2021-44488?
Attackers can exploit CVE-2021-44488 by using crafted input to control the size and input to calls to memcpy in op_fnfnumber in sr_port/op_fnfnumber.c, resulting in memory corruption or application crash.
5
Is there a fix available for CVE-2021-44488?
Please refer to the provided reference link for information on available fixes for CVE-2021-44488.