CVE-2021-44494: Null Pointer Dereference
An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, an attacker can cause calls to ZRead to crash due to a NULL pointer dereference.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-44494?
CVE-2021-44494 is a vulnerability discovered in YottaDB and FIS GT.M that allows an attacker to crash the system through a NULL pointer dereference.
What software is affected by CVE-2021-44494?
YottaDB versions up to and including r1.32 and FIS GT.M versions up to and including V7.0-000 are affected by CVE-2021-44494.
What is the severity of CVE-2021-44494?
CVE-2021-44494 has a severity rating of 7.5, which is considered high.
How can an attacker exploit CVE-2021-44494?
An attacker can exploit CVE-2021-44494 by providing crafted input that triggers a crash in the system's ZRead function.
How can I fix CVE-2021-44494?
To fix CVE-2021-44494, users should update YottaDB to a version beyond r1.32 and FIS GT.M to a version beyond V7.0-000.