Описание
LZ4 bindings use a deprecated C API that is vulnerable to memory corruption, which could lead to arbitrary code execution if called with untrusted user input.
Ссылки
- PatchThird Party Advisory
- Issue TrackingPatchThird Party Advisory
- PatchVendor Advisory
- PatchThird Party Advisory
- Issue TrackingPatchThird Party Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2014-07-11 (исключая)
cpe:2.3:a:cloudflare:golz4:*:*:*:*:*:go:*:*
EPSS
Процентиль: 63%
0.01067
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-787
CWE-787
Связанные уязвимости
CVSS3: 9.8
redhat
больше 3 лет назад
LZ4 bindings use a deprecated C API that is vulnerable to memory corruption, which could lead to arbitrary code execution if called with untrusted user input.
EPSS
Процентиль: 63%
0.01067
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-787
CWE-787