CVE-2021-3520
published 2021-06-02CVE-2021-3520: There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling…
PriorityP350critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.22%
86.7th percentile
There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | lz4 | < lz4 1.9.3-2 (bookworm) | lz4 1.9.3-2 (bookworm) |
| lz4_project | lz4 | — | — |
| lz4_project | lz4 | >= 0 < 1.9.3-2 | 1.9.3-2 |
| lz4_project | lz4 | >= 0 < 1.9.3-2 | 1.9.3-2 |
| lz4_project | lz4 | >= 0 < 1.9.3-2 | 1.9.3-2 |
| lz4_project | lz4 | >= 0 < 1.9.3-2 | 1.9.3-2 |
| lz4_project | lz4 | >= 1.8.3 < 1.9.4 | 1.9.4 |
| oracle | communications_cloud_native_core_policy | — | — |
| oracle | zfs_storage_appliance_kit | — | — |
| splunk | universal_forwarder | — | — |
| splunk | universal_forwarder | >= 8.2.0 < 8.2.12 | 8.2.12 |
| splunk | universal_forwarder | >= 9.0.0 < 9.0.6 | 9.0.6 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
ghsa9.8CRITICAL
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
lz4-sys vulnerable to memory corruption via issue in liblz4
ghsa·2022-09-01·CVSS 9.8
CVE-2021-3520 [CRITICAL] CWE-190 lz4-sys vulnerable to memory corruption via issue in liblz4
lz4-sys vulnerable to memory corruption via issue in liblz4
lz4-sys up to v1.9.3 bundles a version of liblz4 that is vulnerable to
[CVE-2021-3520](https://nvd.nist.gov/vuln/detail/CVE-2021-3520).
Attackers could craft a payload that triggers an integer overflow upon
decompression, causing an out-of-bounds write.
The flaw has been corrected in version v1.9.4 of liblz4, which is included
in lz4-sys 1.9.4.
OSV
lz4-sys vulnerable to memory corruption via issue in liblz4
osv·2022-09-01·CVSS 9.8
CVE-2021-3520 [CRITICAL] lz4-sys vulnerable to memory corruption via issue in liblz4
lz4-sys vulnerable to memory corruption via issue in liblz4
lz4-sys up to v1.9.3 bundles a version of liblz4 that is vulnerable to
[CVE-2021-3520](https://nvd.nist.gov/vuln/detail/CVE-2021-3520).
Attackers could craft a payload that triggers an integer overflow upon
decompression, causing an out-of-bounds write.
The flaw has been corrected in version v1.9.4 of liblz4, which is included
in lz4-sys 1.9.4.
OSV
Memory corruption in liblz4
osv·2022-08-25·CVSS 9.8
CVE-2021-3520 [CRITICAL] Memory corruption in liblz4
Memory corruption in liblz4
lz4-sys up to v1.9.3 bundles a version of liblz4 that is vulnerable to
[CVE-2021-3520](https://nvd.nist.gov/vuln/detail/CVE-2021-3520).
Attackers could craft a payload that triggers an integer overflow upon
decompression, causing an out-of-bounds write.
The flaw has been corrected in version v1.9.4 of liblz4, which is included
in lz4-sys 1.9.4.
GHSA
GHSA-gmc7-pqv9-966m: There's a flaw in lz4
ghsa_unreviewed·2022-05-24
CVE-2021-3520 [CRITICAL] CWE-190 GHSA-gmc7-pqv9-966m: There's a flaw in lz4
There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.
OSV
CVE-2021-3520: There's a flaw in lz4
osv·2021-06-02·CVSS 9.8
CVE-2021-3520 [CRITICAL] CVE-2021-3520: There's a flaw in lz4
There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Oracle
Oracle Oracle Communications Risk Matrix: Policy (lz4) — CVE-2021-3520
vendor_oracle·2022-04-15·CVSS 9.8
CVE-2021-3520 [CRITICAL] Oracle Oracle Communications Risk Matrix: Policy (lz4) — CVE-2021-3520
Oracle Oracle Communications Risk Matrix: Policy (lz4) vulnerability
CVE: CVE-2021-3520
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Ubuntu
LZ4 vulnerability
vendor_ubuntu·2021-05-31
CVE-2021-3520 LZ4 vulnerability
Title: LZ4 vulnerability
Summary: LZ4 could be made to crash or run programs if it opened a specially crafted
file.
USN-4968-1 fixed a vulnerability in LZ4. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that LZ4 incorrectly handled certain memory operations.
If a user or automated system were tricked into uncompressing a specially-
crafted LZ4 file, a remote attacker could use this issue to cause LZ4 to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
LZ4 vulnerability
vendor_ubuntu·2021-05-26
CVE-2021-3520 LZ4 vulnerability
Title: LZ4 vulnerability
Summary: LZ4 could be made to crash or run programs if it opened a specially crafted
file.
It was discovered that LZ4 incorrectly handled certain memory operations.
If a user or automated system were tricked into uncompressing a specially-
crafted LZ4 file, a remote attacker could use this issue to cause LZ4 to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
lz4: memory corruption due to an integer overflow bug caused by memmove argument
vendor_redhat·2021-04-28·CVSS 9.8
CVE-2021-3520 [CRITICAL] CWE-787 lz4: memory corruption due to an integer overflow bug caused by memmove argument
lz4: memory corruption due to an integer overflow bug caused by memmove argument
There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.
There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality
Debian
CVE-2021-3520: lz4 - There's a flaw in lz4. An attacker who submits a crafted file to an application ...
vendor_debian·2021·CVSS 9.8
CVE-2021-3520 [CRITICAL] CVE-2021-3520: lz4 - There's a flaw in lz4. An attacker who submits a crafted file to an application ...
There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.
Scope: local
bookworm: resolved (fixed in 1.9.3-2)
bullseye: resolved (fixed in 1.9.3-2)
forky: resolved (fixed in 1.9.3-2)
sid: resolved (fixed in 1.9.3-2)
trixie: resolved (fixed in 1.9.3-2)
No detection rules found.
No public exploits indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1954559https://security.netapp.com/advisory/ntap-20211104-0005/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1954559https://security.netapp.com/advisory/ntap-20211104-0005/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2021-06-02
Published