CVE Database
/

CVE-2019-17543

Back to search

CVE-2019-17543

Published: Oct 14, 2019

Modified: Aug 5, 2024

PUBLISHED

Description

LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize), affecting applications that call LZ4_compress_fast with a large input. (This issue can also lead to data corruption.) NOTE: the vendor states "only a few specific / uncommon usages of the API are at risk."

VendorProductVersions

n/a

n/a

affected
n/a

References

openSUSE-SU-2019:2399
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2019:2398
vendor-advisory
x_refsource_SUSE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now