CVE-2019-11922
Summary
| CVE | CVE-2019-11922 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-07-25 21:15:00 UTC |
| Updated | 2020-10-20 22:15:00 UTC |
| Description | A race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to write bytes out of bounds if an output buffer smaller than the recommended size was used. |
Risk And Classification
Problem Types: CWE-362
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [security-announce] openSUSE-SU-2019:1845-1: moderate: Security update f | SUSE | lists.opensuse.org | |
| fixed T36302471 by Cyan4973 · Pull Request #1404 · facebook/zstd · GitHub | MISC | github.com | Patch, Third Party Advisory |
| USN-4108-1: Zstandard vulnerability | Ubuntu security notices | Ubuntu | UBUNTU | usn.ubuntu.com | |
| Oracle Critical Patch Update Advisory - October 2020 | MISC | www.oracle.com | |
| CONFIRM | www.facebook.com | Vendor Advisory | |
| [security-announce] openSUSE-SU-2019:2008-1: moderate: Security update f | SUSE | lists.opensuse.org | |
| [security-announce] openSUSE-SU-2019:1952-1: moderate: Security update f | SUSE | lists.opensuse.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 20288 Oracle Database 19c Critical OJVM Patch Update - October 2020
- 500835 Alpine Linux Security Update for zstd
- 504572 Alpine Linux Security Update for zstd
- 671889 EulerOS Security Update for zstd (EulerOS-SA-2022-1957)
- 671941 EulerOS Security Update for zstd (EulerOS-SA-2022-2017)
- 671955 EulerOS Security Update for zstd (EulerOS-SA-2022-1987)