UBUNTU-CVE-2021-3520
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-3520
UBUNTU-CVE-2021-3520
Summary:
Details: There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.
References: https://ubuntu.com/security/CVE-2021-3520, https://github.com/lz4/lz4/pull/972, https://ubuntu.com/security/notices/USN-4968-1, https://ubuntu.com/security/notices/USN-4968-2, https://www.cve.org/CVERecord?id=CVE-2021-3520
Affected packages
Package
Name: lz4
Purl: pkg:deb/ubuntu/[email protected]~r114-2ubuntu1+esm2?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
