Back to search
CVE-2014-4715
Published: Jul 3, 2014
Modified: Aug 6, 2024
PUBLISHED
Description
Yann Collet LZ4 before r119, when used on certain 32-bit platforms that allocate memory beyond 0x80000000, does not properly detect integer overflows, which allows context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted Literal Run, a different vulnerability than CVE-2014-4611.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://code.google.com/p/lz4/source/detail?r=119
x_refsource_CONFIRM
59770
third-party-advisory
x_refsource_SECUNIA
https://code.google.com/p/lz4/issues/detail?id=134
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now