CVE-2019-17543
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize), affecting applications that call LZ4_compress_fast with a large input. (This issue can also lead to data corruption.) NOTE: the vendor states "only a few specific / uncommon usages of the API are at risk."
LZ4 versiones anteriores a 1.9.2, presenta un desbordamiento de búfer en la región heap de la memoria en LZ4_write32 (relacionado con la función LZ4_compress_destSize), que afecta a las aplicaciones que llaman a LZ4_compress_fast con una entrada larga. (Este problema también puede conllevar a la corrupción de datos). NOTA: el fabricante indica que "solo unos pocos usos específicos / poco comunes de la API están en riesgo".
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-10-14 CVE Reserved
- 2019-10-14 CVE Published
- 2024-08-05 CVE Updated
- 2024-10-07 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-787: Out-of-bounds Write
CAPEC
References (19)
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/lz4/lz4/pull/756 | 2023-11-07 | |
https://github.com/lz4/lz4/pull/760 | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Lz4 Project Search vendor "Lz4 Project" | Lz4 Search vendor "Lz4 Project" for product "Lz4" | < 1.9.2 Search vendor "Lz4 Project" for product "Lz4" and version " < 1.9.2" | - |
Affected
|