Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-36124

Опубликовано: 04 июн. 2024
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

iq80 Snappy is a compression/decompression library. When uncompressing certain data, Snappy tries to read outside the bounds of the given byte arrays. Because Snappy uses the JDK class sun.misc.Unsafe to speed up memory access, no additional bounds checks are performed and this has similar security consequences as out-of-bounds access in C or C++, namely it can lead to non-deterministic behavior or crash the JVM. iq80 Snappy is not actively maintained anymore. As quick fix users can upgrade to version 0.5.

A flaw was found in the iq80 Snappy compression/decompression library. When uncompressing certain data, Snappy tries to read outside the bounds of the given byte arrays. Because Snappy uses the JDK class sun.misc.Unsafe to speed up memory access, no additional bounds checks are performed, and this has similar security consequences as out-of-bounds access in C or C++. This issue can lead to non-deterministic behavior or crash the JVM.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
AMQ ClientssnappyNot affected
A-MQ Clients 2snappyAffected
Cryostat 2snappyNot affected
Logging Subsystem for Red Hat OpenShiftsnappyAffected
Migration Toolkit for Applications 6snappyWill not fix
Migration Toolkit for RuntimessnappyWill not fix
OpenShift ServerlesssnappyNot affected
Red Hat AMQ Broker 7snappyNot affected
Red Hat Ansible Automation Platform 2snappyNot affected
Red Hat build of Apache Camel 4 for Quarkus 3snappyNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2290551snappy: tries to read outside the bounds of the given byte arrays

EPSS

Процентиль: 47%
0.00237
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 1 года назад

iq80 Snappy is a compression/decompression library. When uncompressing certain data, Snappy tries to read outside the bounds of the given byte arrays. Because Snappy uses the JDK class `sun.misc.Unsafe` to speed up memory access, no additional bounds checks are performed and this has similar security consequences as out-of-bounds access in C or C++, namely it can lead to non-deterministic behavior or crash the JVM. iq80 Snappy is not actively maintained anymore. As quick fix users can upgrade to version 0.5.

CVSS3: 5.3
nvd
больше 1 года назад

iq80 Snappy is a compression/decompression library. When uncompressing certain data, Snappy tries to read outside the bounds of the given byte arrays. Because Snappy uses the JDK class `sun.misc.Unsafe` to speed up memory access, no additional bounds checks are performed and this has similar security consequences as out-of-bounds access in C or C++, namely it can lead to non-deterministic behavior or crash the JVM. iq80 Snappy is not actively maintained anymore. As quick fix users can upgrade to version 0.5.

CVSS3: 5.3
github
больше 1 года назад

iq80 Snappy out-of-bounds read when uncompressing data, leading to JVM crash

EPSS

Процентиль: 47%
0.00237
Низкий

5.3 Medium

CVSS3