CVE Database
/

CVE-2019-12410

Back to search

CVE-2019-12410

Published: Nov 8, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

While investigating UBSAN errors in https://github.com/apache/arrow/pull/5365 it was discovered Apache Arrow versions 0.12.0 to 0.14.1, left memory Array data uninitialized when reading RLE null data from parquet. This affected the C++, Python, Ruby and R implementations. The uninitialized memory could potentially be shared if are transmitted over the wire (for instance with Flight) or persisted in the streaming IPC and file formats.

VendorProductVersions

Apache Software Foundation

Apache Arrow

affected
Apache Arrow 0.12.0 to 0.14.1

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now