LZ4 'lz4.c' Memory Corruption Vulnerability
BID:68218
Info
LZ4 'lz4.c' Memory Corruption Vulnerability
| Bugtraq ID: | 68218 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2014-4611 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 26 2014 12:00AM |
| Updated: | Apr 13 2015 09:24PM |
| Credit: | Ludvig Strigeus and Don A. Bailey |
| Vulnerable: |
Yann Collet LZ4 0 Ubuntu Ubuntu Linux 14.04 LTS Ubuntu Ubuntu Linux 13.10 Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 |
| Not Vulnerable: | |
Discussion
LZ4 'lz4.c' Memory Corruption Vulnerability
LZ4 is prone to a memory-corruption vulnerability.
A local attacker can exploit this issue to execute arbitrary code or crash the affected application.
LZ4 is prone to a memory-corruption vulnerability.
A local attacker can exploit this issue to execute arbitrary code or crash the affected application.
Exploit / POC
LZ4 'lz4.c' Memory Corruption Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
LZ4 'lz4.c' Memory Corruption Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
LZ4 'lz4.c' Memory Corruption Vulnerability
References:
References:
- LMS-2014-06-16-6: LZ4 Core (seclists.org)
- LZ4 Google Code Page (Yann Collet)
- Security: LZ4_uncompress can crash on invalid input #2 (Yann Collet)