Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2021-2575

Опубликовано: 30 июн. 2021
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2021-2575: lz4 security update (MODERATE)

[1.8.3-3]

  • Fix memory corruption due to an integer overflow _ Resolves: CVE-2021-3520

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

lz4

1.8.3-3.el8_4

lz4-devel

1.8.3-3.el8_4

lz4-libs

1.8.3-3.el8_4

Oracle Linux x86_64

lz4

1.8.3-3.el8_4

lz4-devel

1.8.3-3.el8_4

lz4-libs

1.8.3-3.el8_4

Связанные CVE

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 4 лет назад

There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.

CVSS3: 8.6
redhat
больше 4 лет назад

There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.

CVSS3: 9.8
nvd
больше 4 лет назад

There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.

CVSS3: 9.8
debian
больше 4 лет назад

There's a flaw in lz4. An attacker who submits a crafted file to an ap ...

suse-cvrf
больше 4 лет назад

Security update for lz4