CVE-2019-12410

CWE-9096 documents5 sources
Severity
7.5HIGH
EPSS
5.3%
top 9.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 8
Latest updateMay 24

Description

While investigating UBSAN errors in https://github.com/apache/arrow/pull/5365 it was discovered Apache Arrow versions 0.12.0 to 0.14.1, left memory Array data uninitialized when reading RLE null data from parquet. This affected the C++, Python, Ruby and R implementations. The uninitialized memory could potentially be shared if are transmitted over the wire (for instance with Flight) or persisted in the streaming IPC and file formats.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

NVDapache/arrow0.12.00.14.1
CVEListV5apache_software_foundation/apache_arrowApache Arrow 0.12.0 to 0.14.1
PyPIpyarrow0.12.00.15.1+1
RubyGemsred-arrow0.12.00.15.1

🔴Vulnerability Details

4
OSV
Missing Initialization of Resource in Apache Arrow2022-05-24
GHSA
Missing Initialization of Resource in Apache Arrow2022-05-24
CVEList
CVE-2019-12410: While investigating UBSAN errors in https://github2019-11-08
OSV
CVE-2019-12410: While investigating UBSAN errors in https://github2019-11-08

📋Vendor Advisories

1
Debian
CVE-2019-12410: apache-arrow - While investigating UBSAN errors in https://github.com/apache/arrow/pull/5365 it...2019
CVE-2019-12410 (HIGH CVSS 7.5) | While investigating UBSAN errors in | cvebase.io