CVE-2021-44506: Null Pointer Dereference
Published Apr 15, 2022
·Updated
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of input validation in calls to doverify in srunix/doverify.c allows attackers to attempt to jump to a NULL pointer by corrupting a function pointer.
Affected Software
2 affected componentsFixes available
YottaDB GT.M<=7.0-000
debian/fis-gtm<=6.3-014-3
7.0-005-17.1-006-1
Remediation
Patch Available
Event History
Apr 15, 2022
CVE Published
via MITRE·05:55 PM
Data Sourced
via MITRE·05:55 PM
Description
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Apr 11, 2025
Data Sourced
via Ubuntu·08:38 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·08:38 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-44506?
CVE-2021-44506 is a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2021-44506?
To fix CVE-2021-44506, you should upgrade FIS GT.M to a version higher than 7.0-000.
3
What type of vulnerability is CVE-2021-44506?
CVE-2021-44506 is a code execution vulnerability caused by a lack of input validation.
4
Which software versions are affected by CVE-2021-44506?
CVE-2021-44506 affects FIS GT.M versions up to and including 7.0-000.
5
Can CVE-2021-44506 be exploited remotely?
Yes, CVE-2021-44506 can be exploited remotely due to the nature of the vulnerability.