Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2021:2575

Опубликовано: 22 июл. 2021
Источник: rocky
Оценка: Moderate

Описание

Moderate: lz4 security update

For more information visit https://errata.rockylinux.org/RLSA-2021:2575

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
lz4x86_643.el8_4lz4-1.8.3-3.el8_4.x86_64.rpm
lz4-develx86_643.el8_4lz4-devel-1.8.3-3.el8_4.x86_64.rpm
lz4-libsx86_643.el8_4lz4-libs-1.8.3-3.el8_4.x86_64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 4 лет назад

There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.

CVSS3: 8.6
redhat
больше 4 лет назад

There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.

CVSS3: 9.8
nvd
больше 4 лет назад

There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.

CVSS3: 9.8
debian
больше 4 лет назад

There's a flaw in lz4. An attacker who submits a crafted file to an ap ...

suse-cvrf
больше 4 лет назад

Security update for lz4