CVE-2021-44508: Null Pointer Dereference
Published Apr 15, 2022
·Updated
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of NULL checks in calls to iousopen in srunix/iousopen.c allows attackers to crash the application by dereferencing a NULL pointer.
Affected Software
2 affected componentsFixes available
Fisglobal Gt.m<=7.0-000
debian/fis-gtm<=6.3-014-3
7.0-005-17.1-006-1
Remediation
Patch Available
Event History
Apr 15, 2022
CVE Published
via MITRE·05:56 PM
Data Sourced
via MITRE·05:56 PM
Description
Apr 7, 2025
Data Sourced
via Launchpad·08:37 PM
Description
Apr 11, 2025
Data Sourced
via Ubuntu·08:38 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-44508?
CVE-2021-44508 is considered to have a high severity due to its potential to cause application crashes.
2
How do I fix CVE-2021-44508?
To fix CVE-2021-44508, upgrade to version 7.0-005-1 or 7.1-006-1 of FIS GT.M.
3
What types of attacks can exploit CVE-2021-44508?
CVE-2021-44508 can be exploited through denial of service attacks by dereferencing a NULL pointer.
4
Which versions of FIS GT.M are affected by CVE-2021-44508?
FIS GT.M versions up to 7.0-000 are affected by CVE-2021-44508.
5
Is there a specific platform or environment vulnerable to CVE-2021-44508?
CVE-2021-44508 affects systems utilizing FIS GT.M, particularly within Unix and Linux environments.