[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256040

 
 

909

 
 

199103

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

lz4: heap-based buffer overflow in LZ4_write32 (CVE-2019-17543)

ID: oval:org.secpod.oval:def:1802013Date: (C)2022-03-25   (M)2023-11-10
Class: PATCHFamily: unix




LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 , affecting applications that call LZ4_compress_fast with a large input. NOTE: the vendor states "only a few specific / uncommon usages of the API are at risk."

Platform:
Alpine Linux 3.10
Alpine Linux 3.11
Alpine Linux 3.12
Alpine Linux 3.13
Alpine Linux 3.14
Alpine Linux 3.15
Product:
lz4
Reference:
10919
CVE-2019-17543
CVE    1
CVE-2019-17543
CPE    3
cpe:/o:alpinelinux:alpine_linux:3.11
cpe:/o:alpinelinux:alpine_linux:3.10
cpe:/a:yann_collet:lz4

© SecPod Technologies