Описание
LZ4 bindings use a deprecated C API that is vulnerable to memory corruption, which could lead to arbitrary code execution if called with untrusted user input.
Ссылки
- PatchThird Party Advisory
- Issue TrackingPatchThird Party Advisory
- PatchVendor Advisory
- PatchThird Party Advisory
- Issue TrackingPatchThird Party Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2014-07-11 (исключая)
cpe:2.3:a:cloudflare:golz4:*:*:*:*:*:go:*:*
EPSS
Процентиль: 75%
0.00874
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-787
CWE-787
Связанные уязвимости
CVSS3: 9.8
redhat
около 3 лет назад
LZ4 bindings use a deprecated C API that is vulnerable to memory corruption, which could lead to arbitrary code execution if called with untrusted user input.
EPSS
Процентиль: 75%
0.00874
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-787
CWE-787