QID 671056
Date Published: 2021-11-29
QID 671056: EulerOS Security Update for lz4 (EulerOS-SA-2019-2291)
Lz4 is an extremely fast loss-less compression algorithm, providing compression speed at 400 mb/s per core, scalable with multi-core cpu.
It also features an extremely fast decoder, with speed in multiple gb/s per core, typically reaching ram speed limits on multi-core systems.
Security fix(es): lz4 before 1.9.2 has a heap-based buffer overflow in lz4_write32 (related to lz4_compress_destsize), affecting applications that call lz4_compress_fast with a large input. (
This issue can also lead to data corruption.)
Note: the vendor states "only a few specific / uncommon usages of the api are at risk.
"(cve-2019-17543)
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
An arbitrary attacker may exploit this vulnerability to compromise the system.
CVEs related to QID 671056
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| EulerOS-SA-2019-2291 | EulerOS V2.0SP8 |
|