CVE-2021-44490: High severity yottadb vulnerability
An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can cause a calculation of the size of calls to memset in opfnj3 in srport/opfnj3.c to result in an extremely large value in order to cause a segmentation fault and crash the application. This is a "- (digs < 1 ? 1 : digs)" subtraction.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-44490?
CVE-2021-44490 is a vulnerability discovered in YottaDB through r1.32 and V7.0-000 that allows attackers to cause a segmentation fault and crash the application.
What is the severity of CVE-2021-44490?
The severity of CVE-2021-44490 is rated as high with a severity value of 7.5.
Which software is affected by CVE-2021-44490?
The Fisglobal Gt.m version 7.0-000 and Yottadb Yottadb version up to 1.32 are affected by CVE-2021-44490.
How can an attacker exploit CVE-2021-44490?
Attackers can exploit CVE-2021-44490 by using crafted input to cause an extremely large value during size calculation, leading to a segmentation fault and application crash.
Is there a fix for CVE-2021-44490?
A fix for CVE-2021-44490 may be available from the official vendors. It is recommended to update to a fixed version once it becomes available.