CVE-2021-44498: Null Pointer Dereference
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, attackers can cause a type to be incorrectly initialized in the function fincr in srport/fincr.c and cause a crash due to a NULL pointer dereference.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-44498.
What software is affected by this vulnerability?
The GT.M software versions up to and including V7.0-000 are affected by this vulnerability.
What is the severity rating of CVE-2021-44498?
The severity rating of CVE-2021-44498 is high, with a severity value of 7.5.
How can attackers exploit this vulnerability?
Attackers can exploit this vulnerability by using crafted input to cause a type to be incorrectly initialized in the function f_incr in sr_port/f_incr.c and cause a crash due to a NULL pointer dereference.
Are there any references related to this vulnerability?
Yes, you can find more information about this vulnerability at the following references: [Reference 1](http://tinco.pair.com/bhaskar/gtm/doc/articles/GTM_V7.0-002_Release_Notes.html), [Reference 2](https://gitlab.com/YottaDB/DB/YDB/-/issues/828), [Reference 3](https://sourceforge.net/projects/fis-gtm/files/).