PT-2021-24316 · Mdb Tools · Mdb Tools

Published

2021-12-31

·

Updated

2022-12-09

·

CVE-2021-45926

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: MDB Tools (aka mdbtools) version 0.9.2
Description: The issue is a stack-based buffer overflow in the mdb numeric to string function, which is called from mdb xfer bound data and mdb attempt bind. This overflow occurs at the memory address 0x7ffd0c689be0.
Recommendations: For MDB Tools (aka mdbtools) version 0.9.2, consider applying a patch or fix that addresses the stack-based buffer overflow in the mdb numeric to string function. As a temporary workaround, consider restricting the use of the mdb numeric to string function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2021-45926

Affected Products

Mdb Tools