Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-11922

Опубликовано: 25 июл. 2019
Источник: debian
EPSS Низкий

Описание

A race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to write bytes out of bounds if an output buffer smaller than the recommended size was used.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libzstdfixed1.3.8+dfsg-2package
libzstdnot-affectedstretchpackage

Примечания

  • https://github.com/facebook/zstd/commit/3e5cdf1b6a85843e991d7d10f6a2567c15580da0

EPSS

Процентиль: 70%
0.00634
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 6 лет назад

A race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to write bytes out of bounds if an output buffer smaller than the recommended size was used.

CVSS3: 8.1
redhat
больше 3 лет назад

A race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to write bytes out of bounds if an output buffer smaller than the recommended size was used.

CVSS3: 8.1
nvd
больше 6 лет назад

A race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to write bytes out of bounds if an output buffer smaller than the recommended size was used.

suse-cvrf
больше 6 лет назад

Security update for zstd

suse-cvrf
больше 6 лет назад

Security update for zstd

EPSS

Процентиль: 70%
0.00634
Низкий