PT-2019-14589 · Lmdb+2 · Py-Lmdb+2
Published
2019-09-11
·
Updated
2026-03-25
·
CVE-2019-16227
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
py-lmdb version 0.97
Description
An issue was discovered in py-lmdb where for certain values of
mn flags, mdb cursor set triggers a memcpy with an invalid write operation within mdb xcursor init1. This issue occurs when accessing a data.mdb file supplied by an attacker.Recommendations
For py-lmdb version 0.97, consider restricting access to the
mdb cursor set function until a patch is available, especially when handling data.mdb files from untrusted sources. As a temporary workaround, avoid using certain values of mn flags that trigger the invalid write operation within mdb xcursor init1.Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Debian
Py-Lmdb