An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of input validation in calls to do_verify in sr_unix/do_verify.c allows attackers to attempt to jump to a NULL pointer by corrupting a function pointer.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade fis-gtm | Jul 30, 2024 | Apr 15, 2022 |
| Ubuntu | — | Upgrade fis-gtm-6.2-002 (Ubuntu Pro)Upgrade fis-gtm-6.3-014 (Ubuntu Pro)Upgrade fis-gtm-6.3-007 (Ubuntu Pro)Upgrade fis-gtm-6.3-003a (Ubuntu Pro)Upgrade fis-gtm (Ubuntu Pro) | Apr 9, 2025 | Apr 15, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub