Description
A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause buffer overrun.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0287 | A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause buffer overrun. |
Github GHSA |
GHSA-5c9c-6x87-f9vm | zstd vulnerable to buffer overrun |
References
History
Sat, 01 Mar 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
threat_severity
|
threat_severity
|
Tue, 18 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-02-18T17:23:22.964Z
Reserved: 2023-01-31T00:00:00.000Z
Link: CVE-2022-4899
Updated: 2024-08-03T01:55:46.209Z
Status : Modified
Published: 2023-03-31T20:15:07.213
Modified: 2025-02-18T18:15:14.023
Link: CVE-2022-4899
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA