UBUNTU-CVE-2021-44504
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-44504
Summary:
Details: An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause a size variable, stored as an signed int, to equal an extremely large value, which is interpreted as a negative value during a check. This value is then used in a memcpy call on the stack, causing a memory segmentation fault.
References: https://ubuntu.com/security/CVE-2021-44504, http://tinco.pair.com/bhaskar/gtm/doc/articles/GTM_V7.0-002_Release_Notes.html, https://gitlab.com/YottaDB/DB/YDB/-/issues/828, https://www.cve.org/CVERecord?id=CVE-2021-44504
Affected packages
Package
Name: fis-gtm
Purl: pkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
