CVE-2019-16228 describes a divide-by-zero error in the py-lmdb 0.97 library, specifically within the mdb_env_open2 function. This vulnerability occurs when an attacker provides a malicious data.mdb file that causes a size field to be zero, leading to a system crash. With a CVSS score of 7.5 (High), this vulnerability is remotely exploitable with low attack complexity, resulting in a high availability impact (denial of service). There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.97CPE matchmatch criteria | cpe:2.3:a:py-lmdb_project:py-lmdb:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.