Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-17543

Опубликовано: 17 июл. 2019
Источник: redhat
CVSS3: 8.1

Описание

LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize), affecting applications that call LZ4_compress_fast with a large input. (This issue can also lead to data corruption.) NOTE: the vendor states "only a few specific / uncommon usages of the API are at risk."

Отчет

According to upstream, this flaw cannot be exploited under normal, documented use of the LZ4 library API. Additionally, the flaw is present only in the LZ4 library itself, and the application binaries shipped with this package are not affected. Red Hat OpenStack Platform 10 includes an older version of LZ4 that contains the flawed code. However, OpenStack has been using RHEL's updated LZ4 version since RHEL 7.5, so Red Hat is not issuing an update for the OpenStack LZ4 package. This CVE is rated as moderate because Red Hat products do not use the vulnerable version of lz4 in current OpenStack offerings.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7lz4Will not fix
Red Hat OpenStack Platform 10 (Newton)lz4Will not fix
Red Hat Enterprise Linux 8lz4FixedRHSA-2025:1103515.07.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1765316lz4: heap-based buffer overflow in LZ4_write32

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 6 лет назад

LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize), affecting applications that call LZ4_compress_fast with a large input. (This issue can also lead to data corruption.) NOTE: the vendor states "only a few specific / uncommon usages of the API are at risk."

CVSS3: 8.1
nvd
больше 6 лет назад

LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize), affecting applications that call LZ4_compress_fast with a large input. (This issue can also lead to data corruption.) NOTE: the vendor states "only a few specific / uncommon usages of the API are at risk."

CVSS3: 8.1
debian
больше 6 лет назад

LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (rela ...

suse-cvrf
больше 6 лет назад

Security update for lz4

suse-cvrf
больше 6 лет назад

Security update for lz4

8.1 High

CVSS3