UBUNTU-CVE-2019-11922
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-11922
UBUNTU-CVE-2019-11922
Summary:
Details: A race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to write bytes out of bounds if an output buffer smaller than the recommended size was used.
References: https://ubuntu.com/security/CVE-2019-11922, https://github.com/facebook/zstd/pull/1404/commits/3e5cdf1b6a85843e991d7d10f6a2567c15580da0, https://www.facebook.com/security/advisories/cve-2019-11922, https://ubuntu.com/security/notices/USN-4108-1, https://ubuntu.com/security/notices/USN-5593-1, https://www.cve.org/CVERecord?id=CVE-2019-11922
Affected packages
Package
Name: libzstd
Purl: pkg:deb/ubuntu/[email protected]+dfsg-1~ubuntu0.16.04.1+esm2?arch=source&distro=esm-infra/xenial
Affected ranges
Type: ECOSYSTEM
Events:
