CVE-2021-44500: Input Validation
Published Apr 15, 2022
·Updated
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of input validation in calls to ebdiv in srport/ebmuldiv.c allows attackers to crash the application by performing a divide by zero.
Affected Software
2 affected componentsFixes available
Fisglobal Gt.m<=7.0-000
debian/fis-gtm<=6.3-014-3
7.0-005-17.1-006-1
Remediation
Patch Available
Event History
Apr 15, 2022
CVE Published
via MITRE·05:47 PM
Data Sourced
via MITRE·05:47 PM
Description
Apr 7, 2025
Data Sourced
via Ubuntu·08:36 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·08:37 PM
Description
Frequently Asked Questions
1
What is the vulnerability identifier for this issue?
The vulnerability identifier for this issue is CVE-2021-44500.
2
What is the severity of CVE-2021-44500?
The severity of CVE-2021-44500 is high with a CVSS score of 7.5.
3
Which software is affected by CVE-2021-44500?
FIS GT.M through V7.0-000 (related to the YottaDB code base) is affected by CVE-2021-44500.
4
How can an attacker exploit CVE-2021-44500?
An attacker can exploit CVE-2021-44500 by performing a divide by zero, causing the application to crash.
5
Is there a fix available for CVE-2021-44500?
Yes, there is a fix available for CVE-2021-44500. It is recommended to update to a version of FIS GT.M that addresses the issue.