CVE-2021-3520Critical· 9.8▾ MidnightThere's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/o…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.6 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
3.2%
There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.
lz4 >= 1.8.3, < 1.9.4active_iq_unified_managercloud_backupontap_select_deploy_administration_utilitycommunications_cloud_native_core_policy = 1.14.0zfs_storage_appliance_kit = 8.8universal_forwarder >= 8.2.0, < 8.2.12universal_forwarder >= 9.0.0, < 9.0.6universal_forwarder = 9.1.0Upgrade past the affected range:
lz4 1.9.4universal_forwarder 9.0.6Connected by shared product, vendor, weakness, or advisory.
CVE-2019-17543High· 8.1LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize), affecting applications that call LZ4_compress_fast with a large input
CVE-2020-14155Medium· 5.3libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.
CVE-2023-40548High· 7.4A buffer overflow was found in Shim in the 32-bit system
CVE-2018-16301High· 7.8The command-line argument parser in tcpdump before 4.99.0 has a buffer overflow in tcpdump.c:read_infile()
CVE-2022-2285High· 7.8Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.
CVE-2019-14250Medium· 5.5An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32