CVE-2021-44493: Buffer Overflow
An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, an attacker can cause a call to $Extract to force an signed integer holding the size of a buffer to take on a large negative number, which is then used as the length of a memcpy call that occurs on the stack, causing a buffer overflow.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-44493?
The severity of CVE-2021-44493 is high with a severity value of 7.5.
Which software versions are affected by CVE-2021-44493?
YottaDB versions up to r1.32 and FIS GT.M versions up to V7.0-000 are affected by CVE-2021-44493.
How can an attacker exploit CVE-2021-44493?
An attacker can exploit CVE-2021-44493 by using crafted input to cause a call to $Extract to force a signed integer to take on a large negative number, resulting in a buffer overflow.
Are there any available fixes for CVE-2021-44493?
Yes, there are patches and updates available for YottaDB and FIS GT.M to address CVE-2021-44493. It is recommended to update to the latest versions.
Where can I find more information about CVE-2021-44493?
You can find more information about CVE-2021-44493 in the references provided: http://tinco.pair.com/bhaskar/gtm/doc/articles/GTM_V7.0-002_Release_Notes.html, https://gitlab.com/YottaDB/DB/YDB/-/issues/828, https://sourceforge.net/projects/fis-gtm/files/