Описание
A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause buffer overrun.
Релиз | Статус | Примечание |
---|---|---|
bionic | not-affected | code not present |
devel | not-affected | 1.5.4+dfsg2-4 |
esm-apps/xenial | not-affected | code not present |
esm-infra/bionic | not-affected | code not present |
esm-infra/focal | not-affected | code not present |
esm-infra/xenial | not-affected | code not present |
focal | not-affected | code not present |
jammy | needed | |
kinetic | ignored | end of life, was needed |
lunar | not-affected | 1.5.4+dfsg2-4 |
Показывать по
10
EPSS
Процентиль: 43%
0.00205
Низкий
7.5 High
CVSS3
Связанные уязвимости
CVSS3: 7.5
redhat
почти 3 года назад
A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause buffer overrun.
CVSS3: 7.5
nvd
около 2 лет назад
A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause buffer overrun.
CVSS3: 7.5
debian
около 2 лет назад
A vulnerability was found in zstd v1.4.10, where an attacker can suppl ...
EPSS
Процентиль: 43%
0.00205
Низкий
7.5 High
CVSS3