Null Pointer Dereference Vulnerability in YottaDB

Null Pointer Dereference Vulnerability in YottaDB

CVE-2021-44481 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack of parameter validation in calls to memcpy in check_and_set_timeout in sr_unix/ztimeoutroutines.c allows attackers to attempt to read from a NULL pointer.

Learn more about our Web Application Penetration Testing UK.