Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-17543

Опубликовано: 14 окт. 2019
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 6.8
CVSS3: 8.1

Описание

LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize), affecting applications that call LZ4_compress_fast with a large input. (This issue can also lead to data corruption.) NOTE: the vendor states "only a few specific / uncommon usages of the API are at risk."

РелизСтатусПримечание
bionic

not-affected

0.0~r131-2ubuntu3.1
devel

not-affected

1.9.2-2
disco

ignored

end of life
eoan

ignored

end of life
esm-infra-legacy/trusty

not-affected

0.0~r114-2ubuntu1
esm-infra/bionic

not-affected

0.0~r131-2ubuntu3.1
esm-infra/focal

not-affected

1.9.2-2
esm-infra/xenial

not-affected

0.0~r131-2ubuntu2
focal

not-affected

1.9.2-2
groovy

not-affected

1.9.2-2

Показывать по

EPSS

Процентиль: 84%
0.02292
Низкий

6.8 Medium

CVSS2

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
redhat
около 6 лет назад

LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize), affecting applications that call LZ4_compress_fast with a large input. (This issue can also lead to data corruption.) NOTE: the vendor states "only a few specific / uncommon usages of the API are at risk."

CVSS3: 8.1
nvd
почти 6 лет назад

LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize), affecting applications that call LZ4_compress_fast with a large input. (This issue can also lead to data corruption.) NOTE: the vendor states "only a few specific / uncommon usages of the API are at risk."

CVSS3: 8.1
debian
почти 6 лет назад

LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (rela ...

suse-cvrf
почти 6 лет назад

Security update for lz4

suse-cvrf
почти 6 лет назад

Security update for lz4

EPSS

Процентиль: 84%
0.02292
Низкий

6.8 Medium

CVSS2

8.1 High

CVSS3