First published: Fri Jan 14 2022(Updated: )
An untrusted pointer dereference in rec_db_destroy() at rec-db.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/recutils | <=1.8-1<=1.9-2<=1.9-3 | |
GNU Recutils | =1.8.90 | |
Fedora | =35 | |
Fedora | =36 | |
Fedoraproject Fedora | =35 | |
Fedoraproject Fedora | =36 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-46019 is considered medium due to the potential for application crashes.
To fix CVE-2021-46019, update GNU Recutils to version 1.9-4 or later.
CVE-2021-46019 affects GNU Recutils versions up to 1.8.90, including Debian versions 1.8-1, 1.9-2, and 1.9-3.
CVE-2021-46019 impacts systems running Fedora 35 and 36, as well as Debian with the affected versions.
CVE-2021-46019 refers to an untrusted pointer dereference in rec_db_destroy() which can lead to segmentation faults.