Description
LZ4 bindings use a deprecated C API that is vulnerable to memory corruption, which could lead to arbitrary code execution if called with untrusted user input.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-7509 | LZ4 bindings use a deprecated C API that is vulnerable to memory corruption, which could lead to arbitrary code execution if called with untrusted user input. |
Github GHSA |
GHSA-4wp2-8rm2-jgmh | LZ4 vulnerable to Out-of-bounds Write |
References
History
Fri, 11 Apr 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Go
Published:
Updated: 2025-04-11T23:00:46.201Z
Reserved: 2022-07-29T16:08:15.703Z
Link: CVE-2014-125026
Updated: 2024-08-06T14:10:56.370Z
Status : Modified
Published: 2022-12-27T22:15:10.883
Modified: 2025-04-11T23:15:25.373
Link: CVE-2014-125026
OpenCVE Enrichment
No data.
EUVD
Github GHSA