Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cjw4-2w9r-r8mv

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Missing Initialization of Resource in Apache Arrow

While investigating UBSAN errors in https://github.com/apache/arrow/pull/5365 it was discovered Apache Arrow versions 0.12.0 to 0.14.1, left memory Array data uninitialized when reading RLE null data from parquet. This affected the C++, Python, Ruby and R implementations. The uninitialized memory could potentially be shared if are transmitted over the wire (for instance with Flight) or persisted in the streaming IPC and file formats.

Пакеты

Наименование

pyarrow

pip
Затронутые версииВерсия исправления

>= 0.12.0, < 0.15.1

0.15.1

Наименование

red-arrow

rubygems
Затронутые версииВерсия исправления

>= 0.12.0, < 0.15.1

0.15.1

EPSS

Процентиль: 90%
0.05281
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-909

Связанные уязвимости

CVSS3: 7.5
nvd
около 6 лет назад

While investigating UBSAN errors in https://github.com/apache/arrow/pull/5365 it was discovered Apache Arrow versions 0.12.0 to 0.14.1, left memory Array data uninitialized when reading RLE null data from parquet. This affected the C++, Python, Ruby and R implementations. The uninitialized memory could potentially be shared if are transmitted over the wire (for instance with Flight) or persisted in the streaming IPC and file formats.

CVSS3: 7.5
debian
около 6 лет назад

While investigating UBSAN errors in https://github.com/apache/arrow/pu ...

EPSS

Процентиль: 90%
0.05281
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-909