Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-125026

Опубликовано: 27 дек. 2022
Источник: redhat
CVSS3: 9.8

Описание

LZ4 bindings use a deprecated C API that is vulnerable to memory corruption, which could lead to arbitrary code execution if called with untrusted user input.

A flaw was found in the golz4 package. LZ4 bindings use a deprecated C API that is vulnerable to memory corruption, which could lead to arbitrary code execution if called with untrusted user input.

Отчет

The golz4 is a transitive dependency in OpenShift. Hence, the impact for Red Hat OpenShift Container Platform 4 is lowered to moderate.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openshift4/ose-baremetal-installer-rhel8Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-installerNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-installer-artifacts-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2156869golz4: memory corruption vulnerability in golz4

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

LZ4 bindings use a deprecated C API that is vulnerable to memory corruption, which could lead to arbitrary code execution if called with untrusted user input.

CVSS3: 9.8
github
больше 3 лет назад

LZ4 vulnerable to Out-of-bounds Write

9.8 Critical

CVSS3