An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, an attacker can cause calls to ZRead to crash due to a NULL pointer dereference.
The product dereferences a pointer that it expects to be valid but is NULL.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Gt.m | Fisglobal | * | 7.0-000 (including) | 
| Yottadb | Yottadb | * | 1.32 (including) | 
| Fis-gtm | Ubuntu | bionic | * | 
| Fis-gtm | Ubuntu | esm-apps/bionic | * | 
| Fis-gtm | Ubuntu | esm-apps/focal | * | 
| Fis-gtm | Ubuntu | esm-apps/jammy | * | 
| Fis-gtm | Ubuntu | esm-apps/xenial | * | 
| Fis-gtm | Ubuntu | focal | * | 
| Fis-gtm | Ubuntu | impish | * | 
| Fis-gtm | Ubuntu | jammy | * | 
| Fis-gtm | Ubuntu | kinetic | * | 
| Fis-gtm | Ubuntu | lunar | * | 
| Fis-gtm | Ubuntu | mantic | * | 
| Fis-gtm | Ubuntu | upstream | * |