LZ4 'lz4.c' Incomplete Fix CVE-2014-4611 Memory Corruption Vulnerability
BID:69353
Info
LZ4 'lz4.c' Incomplete Fix CVE-2014-4611 Memory Corruption Vulnerability
| Bugtraq ID: | 69353 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 19 2014 12:00AM |
| Updated: | Aug 19 2014 12:00AM |
| Credit: | Jan Beulich |
| Vulnerable: |
Yann Collet LZ4 0 |
| Not Vulnerable: | |
Discussion
LZ4 'lz4.c' Incomplete Fix CVE-2014-4611 Memory Corruption Vulnerability
LZ4 is prone to a memory-corruption vulnerability.
A local attacker can exploit this issue to execute arbitrary code or crash the affected application.
Note: This issue exists due to an incomplete fix for CVE-2014-4611 (LZ4 'lz4.c' Memory Corruption Vulnerability).
LZ4 is prone to a memory-corruption vulnerability.
A local attacker can exploit this issue to execute arbitrary code or crash the affected application.
Note: This issue exists due to an incomplete fix for CVE-2014-4611 (LZ4 'lz4.c' Memory Corruption Vulnerability).
Solution / Fix
LZ4 'lz4.c' Incomplete Fix CVE-2014-4611 Memory Corruption Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.