PT-2014-2057 · Yann Collet+1 · Lz4+1

Publicado

2014-07-01

·

Atualizado

2021-09-28

·

CVE-2014-4715

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions LZ4 versions prior to r119
Description The issue is related to errors in number processing in the LZ4 lossless data compression algorithm. It may allow a remote attacker to cause a denial of service, potentially through memory corruption, by exploiting the vulnerability with a crafted Literal Run.
Recommendations For versions prior to r119, update to version r119 or later to resolve the issue. As a temporary workaround, consider restricting the use of the LZ4 compression algorithm on 32-bit platforms until a patch is available.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-06975
CVE-2014-4715

Produtos afetados

Lz4
Suse