Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-3520

Опубликовано: 02 июн. 2021
Источник: debian
EPSS Низкий

Описание

There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
lz4fixed1.9.3-2package

Примечания

  • https://github.com/lz4/lz4/pull/972

  • Fixed by: https://github.com/lz4/lz4/commit/8301a21773ef61656225e264f4f06ae14462bca7

EPSS

Процентиль: 34%
0.00134
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 4 лет назад

There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.

CVSS3: 8.6
redhat
больше 4 лет назад

There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.

CVSS3: 9.8
nvd
больше 4 лет назад

There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.

suse-cvrf
больше 4 лет назад

Security update for lz4

suse-cvrf
больше 4 лет назад

Security update for lz4

EPSS

Процентиль: 34%
0.00134
Низкий
Уязвимость CVE-2021-3520