{"id":"CVE-2021-44144","aliases":["GHSA-6mmf-v5q7-vw2w","PYSEC-2021-860"],"url":"https://o3.security/vulnerability/CVE-2021-44144","summary":"Asterix Heap-based Buffer Overflow","details":"Croatia Control Asterix 2.8.1 has a heap-based buffer over-read, with additional details to be disclosed at a later date.","published":"2021-11-22T21:15:07.507Z","modified":"2026-07-09T06:01:57.700400Z","cvss":{"score":9.1,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"asterix-decoder","fixedVersion":"0.7.2"}],"fix":{"url":"https://github.com/CroatiaControlLtd/asterix/commit/3f765d387d239ccc44e278a2ffa600fb6a6587f9","label":"CroatiaControlLtd/asterix@3f765d3"},"references":[{"type":"FIX","url":"https://github.com/CroatiaControlLtd/asterix/issues/183"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-44144"},{"type":"WEB","url":"https://github.com/CroatiaControlLtd/asterix/commit/3f765d387d239ccc44e278a2ffa600fb6a6587f9"},{"type":"PACKAGE","url":"https://github.com/CroatiaControlLtd/asterix"},{"type":"WEB","url":"https://github.com/CroatiaControlLtd/asterix/blob/daf33de522d1cdab0e941c025b89e18a0d4d42c6/README.md?plain=1#L7"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/asterix-decoder/PYSEC-2021-860.yaml"},{"type":"WEB","url":"https://web.archive.org/web/20221207104133/https://huntr.dev/bounties/1-other-CroatiaControlLtd/asterix"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T06:01:57.700400Z"}}