CVE-2021-46019: Null Pointer Dereference
Published Jan 14, 2022
·Updated
An untrusted pointer dereference in recdbdestroy() at rec-db.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.
Affected Software
4 affected components
debian/recutils<=1.8-1, <=1.9-2, <=1.9-3
GNU recutils=1.8.90
Fedoraproject Fedora=35
Fedoraproject Fedora=36
Event History
Jan 14, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Dec 4, 2024
Data Sourced
via Launchpad·08:56 PM
Description
Dec 8, 2024
Data Sourced
via Ubuntu·08:56 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-46019?
The severity of CVE-2021-46019 is considered medium due to the potential for application crashes.
2
How do I fix CVE-2021-46019?
To fix CVE-2021-46019, update GNU Recutils to version 1.9-4 or later.
3
What versions of GNU Recutils are affected by CVE-2021-46019?
CVE-2021-46019 affects GNU Recutils versions up to 1.8.90, including Debian versions 1.8-1, 1.9-2, and 1.9-3.
4
Which operating systems are impacted by CVE-2021-46019?
CVE-2021-46019 impacts systems running Fedora 35 and 36, as well as Debian with the affected versions.
5
What is the nature of the vulnerability described in CVE-2021-46019?
CVE-2021-46019 refers to an untrusted pointer dereference in rec_db_destroy() which can lead to segmentation faults.