HIGH
An issue was discovered in py-lmdb 0.97
Published Sep 11, 2019
8.7
HIGHCVSS 4.0
EPSS 1.79%
Description
An issue was discovered in py-lmdb 0.97. There is a divide-by-zero error in the function mdb_env_open2 if mdb_env_read_header obtains a zero value for a certain size field. NOTE: this outcome occurs when accessing a data.mdb file supplied by an attacker.
Affected products
No data.
- ≤ 0.97
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0081 Advisory
- https://github.com/TeamSeri0us/pocs/tree/master/lmdb/FPE x_refsource_MISCExploitThird Party Advisory
- https://github.com/advisories/GHSA-ggwq-vrgp-6gv4 Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/lmdb/PYSEC-2019-240.yaml
- https://nvd.nist.gov/vuln/detail/CVE-2019-16228
- https://pypi.org/project/lmdb
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0081 | Advisory | |
| https://github.com/TeamSeri0us/pocs/tree/master/lmdb/FPE | x_refsource_MISCExploitThird Party Advisory | |
| https://github.com/advisories/GHSA-ggwq-vrgp-6gv4 | Advisory | |
| https://github.com/pypa/advisory-database/tree/main/vulns/lmdb/PYSEC-2019-240.yaml | ||
| https://nvd.nist.gov/vuln/detail/CVE-2019-16228 | ||
| https://pypi.org/project/lmdb |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 11, 2019
Updated Aug 5, 2024
Reserved Sep 11, 2019
Link CVE-2019-16228
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2019-0081 GHSA-GGWQ-VRGP-6GV4 Assigner mitre
Published Sep 11, 2019
Updated Aug 5, 2024
Exploited since n/a
Link EUVD-2019-0081