CVE-2021-44495: Null Pointer Dereference
Published Apr 15, 2022
·Updated
An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, an attacker can cause a NULL pointer dereference after calls to ZPrint.
Affected Software
2 affected components
Fisglobal Gt.m<=7.0-000
YottaDB YottaDB<=1.32
Remediation
Patch Available
Event History
Apr 15, 2022
CVE Published
via MITRE·05:38 PM
Data Sourced
via MITRE·05:38 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-44495.
2
What is the severity of CVE-2021-44495?
The severity of CVE-2021-44495 is high with a severity value of 7.5.
3
Which software versions are affected by CVE-2021-44495?
YottaDB versions up to r1.32 and Fisglobal GT.M versions up to V7.0-000 are affected by CVE-2021-44495.
4
What is the impact of CVE-2021-44495?
An attacker can cause a NULL pointer dereference after calls to ZPrint using crafted input.
5
Are there any available references for CVE-2021-44495?
Yes, you can find references for CVE-2021-44495 at the following links: http://tinco.pair.com/bhaskar/gtm/doc/articles/GTM_V7.0-002_Release_Notes.html, https://gitlab.com/YottaDB/DB/YDB/-/issues/828, https://sourceforge.net/projects/fis-gtm/files/