Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-36124

Опубликовано: 03 июн. 2024
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

iq80 Snappy is a compression/decompression library. When uncompressing certain data, Snappy tries to read outside the bounds of the given byte arrays. Because Snappy uses the JDK class sun.misc.Unsafe to speed up memory access, no additional bounds checks are performed and this has similar security consequences as out-of-bounds access in C or C++, namely it can lead to non-deterministic behavior or crash the JVM. iq80 Snappy is not actively maintained anymore. As quick fix users can upgrade to version 0.5.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:dain:snappy:*:*:*:*:*:*:*:*
Версия до 0.5 (исключая)

EPSS

Процентиль: 47%
0.00237
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-125
CWE-125

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 1 года назад

iq80 Snappy is a compression/decompression library. When uncompressing certain data, Snappy tries to read outside the bounds of the given byte arrays. Because Snappy uses the JDK class `sun.misc.Unsafe` to speed up memory access, no additional bounds checks are performed and this has similar security consequences as out-of-bounds access in C or C++, namely it can lead to non-deterministic behavior or crash the JVM. iq80 Snappy is not actively maintained anymore. As quick fix users can upgrade to version 0.5.

CVSS3: 5.3
redhat
больше 1 года назад

iq80 Snappy is a compression/decompression library. When uncompressing certain data, Snappy tries to read outside the bounds of the given byte arrays. Because Snappy uses the JDK class `sun.misc.Unsafe` to speed up memory access, no additional bounds checks are performed and this has similar security consequences as out-of-bounds access in C or C++, namely it can lead to non-deterministic behavior or crash the JVM. iq80 Snappy is not actively maintained anymore. As quick fix users can upgrade to version 0.5.

CVSS3: 5.3
github
больше 1 года назад

iq80 Snappy out-of-bounds read when uncompressing data, leading to JVM crash

EPSS

Процентиль: 47%
0.00237
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-125
CWE-125