A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause buffer overrun.
References
Configurations
History
21 Nov 2024, 07:36
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/facebook/zstd/issues/3200 - Issue Tracking, Patch | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C63HAGVLQA6FJNDCHR7CNZZL6VSLILB2/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JEHRBBYYTPA4DETOM5XAKGCP37NUTLOA/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QYLDK6ODVC4LJSDULLX6Q2YHTFOWABCN/ - | |
References | () https://security.netapp.com/advisory/ntap-20230725-0005/ - |
25 Jul 2023, 15:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-400 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
CPE | cpe:2.3:a:facebook:zstandard:1.4.10:*:*:*:*:*:*:* | |
References |
|
|
References | (MISC) https://github.com/facebook/zstd/issues/3200 - Issue Tracking, Patch |
31 Mar 2023, 21:24
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-03-31 20:15
Updated : 2025-02-18 18:15
NVD link : CVE-2022-4899
Mitre link : CVE-2022-4899
CVE.ORG link : CVE-2022-4899
JSON object : View
Products Affected
- zstandard
CWE
CWE-400
Uncontrolled Resource Consumption