ZeroHour

CVE-2021-3520

CVSS 3.1
9.8 critical
EPSS
3%p87
Published
()
Modified
Description

There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.

Vendors
lz4 projectnetapporaclesplunk
Products
lz4, active iq unified manager, cloud backup, ontap select deploy administration utility, communications cloud native core policy, zfs storage appliance kit, universal forwarder
Weakness
CWE-190, CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.