CVE-2019-16224 is a critical vulnerability affecting py-lmdb 0.97, where an invalid write operation can occur in the mdb_node_add function due to improper memcpy destination setup under specific md_flags values. This flaw is triggered when processing a malicious data.mdb file provided by an attacker. With a CVSS score of 9.8 (Critical), this vulnerability is remotely exploitable with low attack complexity and can lead to complete compromise of confidentiality, integrity, and availability. Despite its severity, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.97CPE matchmatch criteria | cpe:2.3:a:py-lmdb_project:py-lmdb:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.