CVE-2021-44489: Integer Underflow
Published Apr 15, 2022
·Updated
An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can cause an integer underflow of the size of calls to memset in opfnj3 in srport/opfnj3.c in order to cause a segmentation fault and crash the application. This is a "- digs" subtraction.
Affected Software
2 affected components
Fisglobal Gt.m<=7.0-000
YottaDB YottaDB<=1.32
Event History
Apr 15, 2022
CVE Published
via MITRE·05:24 PM
Data Sourced
via MITRE·05:24 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2021-44489.
2
What is the severity of CVE-2021-44489?
The severity of CVE-2021-44489 is high, with a severity value of 7.5.
3
What is the affected software?
The affected software includes Fisglobal Gt.m versions up to 7.0-000 and Yottadb Yottadb versions up to 1.32.
4
How can attackers exploit CVE-2021-44489?
Attackers can exploit CVE-2021-44489 by using crafted input to cause an integer underflow and crash the application.
5
Is there a fix for CVE-2021-44489?
Yes, please refer to the provided reference link for more information on how to fix CVE-2021-44489.