CVE-2021-44492: Null Pointer Dereference
An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, attackers can cause a type to be incorrectly initialized in the function fincr in srport/fincr.c and cause a crash due to a NULL pointer dereference.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2021-44492.
What is the severity of CVE-2021-44492?
The severity of CVE-2021-44492 is high with a CVSS score of 7.5.
Which software versions are affected by CVE-2021-44492?
YottaDB versions up to r1.32 and Fisglobal GT.M versions up to V7.0-000 are affected by CVE-2021-44492.
How can attackers exploit CVE-2021-44492?
Attackers can cause a crash due to a NULL pointer dereference by using crafted input in the function f_incr in sr_port/f_incr.c.
Are there any references available for more information about CVE-2021-44492?
Yes, you can find more information about CVE-2021-44492 in the following references: [link1](http://tinco.pair.com/bhaskar/gtm/doc/articles/GTM_V7.0-002_Release_Notes.html), [link2](https://gitlab.com/YottaDB/DB/YDB/-/issues/828), [link3](https://sourceforge.net/projects/fis-gtm/files/).