Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2021:1825-1

Опубликовано: 01 июн. 2021
Источник: suse-cvrf

Описание

Security update for lz4

This update for lz4 fixes the following issues:

  • CVE-2021-3520: Fixed memory corruption due to an integer overflow bug caused by memmove argument (bsc#1185438).

Список пакетов

Container bci/bci-init:15.3
liblz4-1-1.9.2-3.3.1
Container bci/dotnet-aspnet:3.1
liblz4-1-1.9.2-3.3.1
Container bci/dotnet-aspnet:5.0
liblz4-1-1.9.2-3.3.1
Container bci/dotnet-aspnet:latest
liblz4-1-1.9.2-3.3.1
Container bci/dotnet-runtime:3.1
liblz4-1-1.9.2-3.3.1
Container bci/dotnet-runtime:5.0
liblz4-1-1.9.2-3.3.1
Container bci/dotnet-runtime:latest
liblz4-1-1.9.2-3.3.1
Container bci/dotnet-sdk:3.1
liblz4-1-1.9.2-3.3.1
Container bci/dotnet-sdk:5.0
liblz4-1-1.9.2-3.3.1
Container bci/dotnet-sdk:latest
liblz4-1-1.9.2-3.3.1
Container bci/golang:1.16
liblz4-1-1.9.2-3.3.1
Container bci/golang:1.17
liblz4-1-1.9.2-3.3.1
Container bci/golang:latest
liblz4-1-1.9.2-3.3.1
Container bci/node:12
liblz4-1-1.9.2-3.3.1
Container bci/node:14
liblz4-1-1.9.2-3.3.1
Container bci/nodejs:latest
liblz4-1-1.9.2-3.3.1
Container bci/openjdk-devel:11
liblz4-1-1.9.2-3.3.1
Container bci/openjdk:latest
liblz4-1-1.9.2-3.3.1
Container bci/python:3
liblz4-1-1.9.2-3.3.1
Container bci/ruby:latest
liblz4-1-1.9.2-3.3.1
Container ses/7.1/ceph/grafana:latest
liblz4-1-1.9.2-3.3.1
Container ses/7.1/ceph/haproxy:latest
liblz4-1-1.9.2-3.3.1
Container ses/7.1/ceph/keepalived:latest
liblz4-1-1.9.2-3.3.1
Container ses/7.1/ceph/prometheus-alertmanager:latest
liblz4-1-1.9.2-3.3.1
Container ses/7.1/ceph/prometheus-node-exporter:latest
liblz4-1-1.9.2-3.3.1
Container ses/7.1/ceph/prometheus-server:latest
liblz4-1-1.9.2-3.3.1
Container ses/7.1/ceph/prometheus-snmp_notifier:latest
liblz4-1-1.9.2-3.3.1
Container ses/7.1/cephcsi/cephcsi:latest
liblz4-1-1.9.2-3.3.1
Container ses/7.1/cephcsi/csi-attacher:v4.1.0
liblz4-1-1.9.2-3.3.1
Container ses/7.1/cephcsi/csi-node-driver-registrar:v2.7.0
liblz4-1-1.9.2-3.3.1
Container ses/7.1/cephcsi/csi-provisioner:v3.4.0
liblz4-1-1.9.2-3.3.1
Container ses/7.1/cephcsi/csi-resizer:v1.7.0
liblz4-1-1.9.2-3.3.1
Container ses/7.1/cephcsi/csi-snapshotter:v6.2.1
liblz4-1-1.9.2-3.3.1
Container ses/7.1/rook/ceph:latest
liblz4-1-1.9.2-3.3.1
Container suse/pcp:latest
liblz4-1-1.9.2-3.3.1
Container suse/rmt-mariadb-client:latest
liblz4-1-1.9.2-3.3.1
Container suse/rmt-mariadb:latest
liblz4-1-1.9.2-3.3.1
Container suse/rmt-nginx:latest
liblz4-1-1.9.2-3.3.1
Container suse/rmt-server:latest
liblz4-1-1.9.2-3.3.1
Container suse/sle-micro-rancher/5.2:latest
liblz4-1-1.9.2-3.3.1
Container suse/sle-micro/5.1/toolbox:latest
liblz4-1-1.9.2-3.3.1
Container suse/sle-micro/5.2/toolbox:latest
liblz4-1-1.9.2-3.3.1
Container suse/sle15:15.3
liblz4-1-1.9.2-3.3.1
Container suse/sles/15.3/cdi-apiserver:1.37.1
liblz4-1-1.9.2-3.3.1
Container suse/sles/15.3/cdi-cloner:1.37.1
liblz4-1-1.9.2-3.3.1
Container suse/sles/15.3/cdi-controller:1.37.1
liblz4-1-1.9.2-3.3.1
Container suse/sles/15.3/cdi-importer:1.37.1
liblz4-1-1.9.2-3.3.1
Container suse/sles/15.3/cdi-operator:1.37.1
liblz4-1-1.9.2-3.3.1
Container suse/sles/15.3/cdi-uploadproxy:1.37.1
liblz4-1-1.9.2-3.3.1
Container suse/sles/15.3/cdi-uploadserver:1.37.1
liblz4-1-1.9.2-3.3.1
Container suse/sles/15.3/libguestfs-tools:0.45.0
liblz4-1-1.9.2-3.3.1
Container suse/sles/15.3/virt-api:0.45.0
liblz4-1-1.9.2-3.3.1
Container suse/sles/15.3/virt-controller:0.45.0
liblz4-1-1.9.2-3.3.1
Container suse/sles/15.3/virt-handler:0.45.0
liblz4-1-1.9.2-3.3.1
Container suse/sles/15.3/virt-launcher:0.45.0
liblz4-1-1.9.2-3.3.1
Container suse/sles/15.3/virt-operator:0.45.0
liblz4-1-1.9.2-3.3.1
Container trento/trento-db:latest
liblz4-1-1.9.2-3.3.1
Container trento/trento-runner:latest
liblz4-1-1.9.2-3.3.1
Image SLES15-SP3-BYOS-Azure
liblz4-1-1.9.2-3.3.1
Image SLES15-SP3-BYOS-EC2-HVM
liblz4-1-1.9.2-3.3.1
Image SLES15-SP3-BYOS-GCE
liblz4-1-1.9.2-3.3.1
Image SLES15-SP3-CHOST-BYOS-Aliyun
liblz4-1-1.9.2-3.3.1
Image SLES15-SP3-CHOST-BYOS-Azure
liblz4-1-1.9.2-3.3.1
Image SLES15-SP3-CHOST-BYOS-EC2
liblz4-1-1.9.2-3.3.1
Image SLES15-SP3-CHOST-BYOS-GCE
liblz4-1-1.9.2-3.3.1
Image SLES15-SP3-CHOST-BYOS-SAP-CCloud
liblz4-1-1.9.2-3.3.1
Image SLES15-SP3-EC2-ECS-HVM
liblz4-1-1.9.2-3.3.1
Image SLES15-SP3-EC2-HVM
liblz4-1-1.9.2-3.3.1
liblz4-1-32bit-1.9.2-3.3.1
Image SLES15-SP3-GCE
liblz4-1-1.9.2-3.3.1
Image SLES15-SP3-HPC-Azure
liblz4-1-1.9.2-3.3.1
Image SLES15-SP3-HPC-BYOS-Azure
liblz4-1-1.9.2-3.3.1
Image SLES15-SP3-HPC-BYOS-EC2-HVM
liblz4-1-1.9.2-3.3.1
Image SLES15-SP3-HPC-BYOS-GCE
liblz4-1-1.9.2-3.3.1
Image SLES15-SP3-Manager-4-2-Proxy-BYOS-Azure
liblz4-1-1.9.2-3.3.1
Image SLES15-SP3-Manager-4-2-Proxy-BYOS-EC2-HVM
liblz4-1-1.9.2-3.3.1
Image SLES15-SP3-Manager-4-2-Proxy-BYOS-GCE
liblz4-1-1.9.2-3.3.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure
liblz4-1-1.9.2-3.3.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM
liblz4-1-1.9.2-3.3.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE
liblz4-1-1.9.2-3.3.1
Image SLES15-SP3-Micro-5-1-BYOS-Azure
liblz4-1-1.9.2-3.3.1
Image SLES15-SP3-Micro-5-1-BYOS-EC2-HVM
liblz4-1-1.9.2-3.3.1
Image SLES15-SP3-Micro-5-1-BYOS-GCE
liblz4-1-1.9.2-3.3.1
Image SLES15-SP3-Micro-5-2-BYOS-Azure
liblz4-1-1.9.2-3.3.1
Image SLES15-SP3-Micro-5-2-BYOS-EC2-HVM
liblz4-1-1.9.2-3.3.1
Image SLES15-SP3-Micro-5-2-BYOS-GCE
liblz4-1-1.9.2-3.3.1
Image SLES15-SP3-Micro-BYOS-GCE
liblz4-1-1.9.2-3.3.1
Image SLES15-SP3-SAP-Azure
liblz4-1-1.9.2-3.3.1
liblz4-1-32bit-1.9.2-3.3.1
Image SLES15-SP3-SAP-Azure-LI-BYOS-Production
liblz4-1-1.9.2-3.3.1
Image SLES15-SP3-SAP-Azure-VLI-BYOS-Production
liblz4-1-1.9.2-3.3.1
Image SLES15-SP3-SAP-BYOS-Azure
liblz4-1-1.9.2-3.3.1
Image SLES15-SP3-SAP-BYOS-EC2-HVM
liblz4-1-1.9.2-3.3.1
Image SLES15-SP3-SAP-BYOS-GCE
liblz4-1-1.9.2-3.3.1
Image SLES15-SP3-SAP-EC2-HVM
liblz4-1-1.9.2-3.3.1
liblz4-1-32bit-1.9.2-3.3.1
Image SLES15-SP3-SAP-GCE
liblz4-1-1.9.2-3.3.1
liblz4-1-32bit-1.9.2-3.3.1
Image SLES15-SP3-SAPCAL-Azure
liblz4-1-1.9.2-3.3.1
liblz4-1-32bit-1.9.2-3.3.1
Image SLES15-SP3-SAPCAL-EC2-HVM
liblz4-1-1.9.2-3.3.1
liblz4-1-32bit-1.9.2-3.3.1
Image SLES15-SP3-SAPCAL-GCE
liblz4-1-1.9.2-3.3.1
liblz4-1-32bit-1.9.2-3.3.1
SUSE Linux Enterprise Module for Basesystem 15 SP3
liblz4-1-1.9.2-3.3.1
liblz4-1-32bit-1.9.2-3.3.1
liblz4-devel-1.9.2-3.3.1
lz4-1.9.2-3.3.1

Описание

There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.


Затронутые продукты
Container bci/bci-init:15.3:liblz4-1-1.9.2-3.3.1
Container bci/dotnet-aspnet:3.1:liblz4-1-1.9.2-3.3.1
Container bci/dotnet-aspnet:5.0:liblz4-1-1.9.2-3.3.1
Container bci/dotnet-aspnet:latest:liblz4-1-1.9.2-3.3.1

Ссылки
Уязвимость SUSE-SU-2021:1825-1