id: PYSEC-2019-240 details: 'An issue was discovered in py-lmdb 0.97. There is a divide-by-zero error in the function mdb_env_open2 if mdb_env_read_header obtains a zero value for a certain size field. NOTE: this outcome occurs when accessing a data.mdb file supplied by an attacker.' aliases: - CVE-2019-16228 - GHSA-ggwq-vrgp-6gv4 modified: '2021-12-14T08:17:08.476513Z' published: '2019-09-11T15:15:00Z' references: - type: WEB url: https://github.com/TeamSeri0us/pocs/tree/master/lmdb/FPE - type: PACKAGE url: https://pypi.org/project/lmdb - type: ADVISORY url: https://nvd.nist.gov/vuln/detail/CVE-2019-16228 - type: ADVISORY url: https://github.com/advisories/GHSA-ggwq-vrgp-6gv4 affected: - package: name: lmdb ecosystem: PyPI purl: pkg:pypi/lmdb ranges: - type: ECOSYSTEM events: - introduced: '0' - fixed: '0.98' versions: - '0.58' - '0.59' - '0.60' - '0.61' - '0.62' - '0.63' - '0.64' - '0.65' - '0.66' - '0.67' - '0.68' - '0.69' - '0.70' - '0.71' - '0.73' - '0.74' - '0.75' - '0.76' - '0.77' - '0.78' - '0.79' - '0.80' - '0.81' - '0.82' - '0.83' - '0.84' - '0.85' - '0.86' - '0.87' - '0.88' - '0.89' - '0.91' - '0.92' - '0.93' - '0.94' - '0.95' - '0.96' - '0.97'