Описание
LZ4 bindings use a deprecated C API that is vulnerable to memory corruption, which could lead to arbitrary code execution if called with untrusted user input.
A flaw was found in the golz4 package. LZ4 bindings use a deprecated C API that is vulnerable to memory corruption, which could lead to arbitrary code execution if called with untrusted user input.
Отчет
The golz4 is a transitive dependency in OpenShift. Hence, the impact for Red Hat OpenShift Container Platform 4 is lowered to moderate.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Container Platform 4 | openshift4/ose-baremetal-installer-rhel8 | Not affected | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-installer | Not affected | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-installer-artifacts-rhel9 | Not affected |
Показывать по
10
Дополнительная информация
Статус:
Critical
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2156869golz4: memory corruption vulnerability in golz4
9.8 Critical
CVSS3
Связанные уязвимости
CVSS3: 9.8
nvd
больше 3 лет назад
LZ4 bindings use a deprecated C API that is vulnerable to memory corruption, which could lead to arbitrary code execution if called with untrusted user input.
9.8 Critical
CVSS3