CVE-2019-17543Out-of-bounds Write in Project LZ4

Severity
8.1HIGHNVD
EPSS
1.4%
top 19.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 14
Latest updateMay 24

Description

LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize), affecting applications that call LZ4_compress_fast with a large input. (This issue can also lead to data corruption.) NOTE: the vendor states "only a few specific / uncommon usages of the API are at risk."

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages2 packages

NVDlz4_project/lz4< 1.9.2
Debianlz4_project/lz4< 1.9.2-1+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-fxrv-74g3-w7qr: LZ4 before 12022-05-24
OSV
CVE-2019-17543: LZ4 before 12019-10-14
CVEList
CVE-2019-17543: LZ4 before 12019-10-14

📋Vendor Advisories

3
Oracle
Oracle Oracle MySQL Risk Matrix: Server: Compiling (LZ4) — CVE-2019-175432021-07-15
Red Hat
lz4: heap-based buffer overflow in LZ4_write322019-07-17
Debian
CVE-2019-17543: lz4 - LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4...2019

💬Community

3
Bugzilla
CVE-2019-17543 lz4: heap-based buffer overflow in LZ4_write32 [epel-6]2019-10-24
Bugzilla
CVE-2019-17543 lz4: heap-based buffer overflow in LZ4_write32 [fedora-all]2019-10-24
Bugzilla
CVE-2019-17543 lz4: heap-based buffer overflow in LZ4_write322019-10-24
CVE-2019-17543 — Out-of-bounds Write in LZ4 Project LZ4 | cvebase