Описание
A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause buffer overrun.
Ссылки
- Issue TrackingPatch
- Issue TrackingPatch
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:facebook:zstandard:1.4.10:*:*:*:*:*:*:*
EPSS
Процентиль: 43%
0.00205
Низкий
7.5 High
CVSS3
Дефекты
CWE-400
CWE-400
CWE-400
Связанные уязвимости
CVSS3: 7.5
ubuntu
около 2 лет назад
A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause buffer overrun.
CVSS3: 7.5
redhat
почти 3 года назад
A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause buffer overrun.
CVSS3: 7.5
debian
около 2 лет назад
A vulnerability was found in zstd v1.4.10, where an attacker can suppl ...
EPSS
Процентиль: 43%
0.00205
Низкий
7.5 High
CVSS3
Дефекты
CWE-400
CWE-400
CWE-400