CVE-2019-16225 is a critical vulnerability affecting py-lmdb 0.97, where improper handling of mp_flags in mdb_page_touch can lead to an invalid write operation. This flaw, triggered by an attacker-supplied data.mdb file, allows for remote code execution with high impact on confidentiality, integrity, and availability, as indicated by its CVSS score of 9.8. Despite its severity, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.97CPE matchmatch criteria | cpe:2.3:a:py-lmdb_project:py-lmdb:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.