Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3520

Опубликовано: 28 апр. 2021
Источник: redhat
CVSS3: 8.6
EPSS Низкий

Описание

There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.

Отчет

This flaw is out of support scope for Red Hat Enterprise Linux 7. To learn more about Red Hat Enterprise Linux support life cycles, please see https://access.redhat.com/support/policy/updates/errata .

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2lz4Not affected
Red Hat build of Quarkuslz4Affected
Red Hat Enterprise Linux 7lz4Out of support scope
Red Hat Enterprise Linux 9lz4Not affected
Red Hat Fuse 7lz4Fix deferred
Red Hat JBoss Fuse 6lz4Out of support scope
Red Hat AMQ Streams 2.1.0lz4FixedRHSA-2022:134513.04.2022
Red Hat AMQ Streams 2.7.0FixedRHSA-2024:352730.05.2024
Red Hat Enterprise Linux 8lz4FixedRHSA-2021:257529.06.2021
Red Hat Migration Toolkit for Containers 1.4rhmtc/openshift-migration-controller-rhel8FixedRHBA-2021:285421.07.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190->CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=1954559lz4: memory corruption due to an integer overflow bug caused by memmove argument

EPSS

Процентиль: 34%
0.00134
Низкий

8.6 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 4 лет назад

There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.

CVSS3: 9.8
nvd
больше 4 лет назад

There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.

CVSS3: 9.8
debian
больше 4 лет назад

There's a flaw in lz4. An attacker who submits a crafted file to an ap ...

suse-cvrf
больше 4 лет назад

Security update for lz4

suse-cvrf
больше 4 лет назад

Security update for lz4

EPSS

Процентиль: 34%
0.00134
Низкий

8.6 High

CVSS3