CVE-2021-44507: Null Pointer Dereference
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of parameter validation in calls to memcpy in strtok in srunix/ztimeoutroutines.c allows attackers to attempt to read from a NULL pointer.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-44507?
CVE-2021-44507 has a severity rating that indicates a potential high risk due to a lack of parameter validation allowing read access from a NULL pointer.
How do I fix CVE-2021-44507?
To fix CVE-2021-44507, upgrade FIS GT.M to a version above 7.0-000 that includes the patched code.
What applications are affected by CVE-2021-44507?
CVE-2021-44507 affects FIS GT.M versions up to and including 7.0-000.
What type of vulnerability is CVE-2021-44507?
CVE-2021-44507 is classified as a vulnerability due to improper input validation in memory operations.
Can CVE-2021-44507 be exploited remotely?
Yes, CVE-2021-44507 can be exploited remotely if an attacker can leverage the vulnerable functionality in the affected software.