CVE-2021-44503: Buffer Overflow
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause a call to vaarg on an empty variadic parameter list, most likely causing a memory segmentation fault.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-44503?
CVE-2021-44503 is a vulnerability discovered in FIS GT.M up to version 7.0-000, related to the YottaDB code base, that allows an attacker to cause a memory segmentation fault by using crafted input.
What is the severity of CVE-2021-44503?
The severity of CVE-2021-44503 is high, with a severity rating of 7.5.
How does CVE-2021-44503 affect FIS GT.M?
CVE-2021-44503 affects FIS GT.M up to version 7.0-000, running on any operating system.
How can an attacker exploit CVE-2021-44503?
An attacker can exploit CVE-2021-44503 by sending crafted input that triggers a call to va_arg on an empty variadic parameter list, leading to a memory segmentation fault.
Is there a fix available for CVE-2021-44503?
Yes, a fix for CVE-2021-44503 is available in the form of GT.M version 7.0-002. It is recommended to upgrade to this version to mitigate the vulnerability.