漏洞信息详情
LZ4 输入验证错误漏洞
漏洞简介
LZ4是一款无损压缩算法。
lz4 1:1.9.3-1 存在输入验证错误漏洞,该漏洞源于整数溢出bug导致一个memmove参数变为负数而导致的潜在内存损坏。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://github.com/lz4/lz4/pull/972
参考网址
来源:N/A
链接:https://www.oracle.com//security-alerts/cpujul2021.html
来源:MISC
链接:https://www.oracle.com/security-alerts/cpuoct2021.html
来源:MISC
链接:https://bugzilla.redhat.com/show_bug.cgi?id=1954559
来源:CONFIRM
链接:https://security.netapp.com/advisory/ntap-20211104-0005/
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021052411
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021052537
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/lz4-integer-overflow-via-memmove-35399
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2657
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2711
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2677
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2897
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2959
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1748
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1791
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163756/Red-Hat-Security-Advisory-2021-3024-01.html
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021090126
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/162870/Ubuntu-Security-Notice-USN-4968-2.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/162836/Ubuntu-Security-Notice-USN-4968-1.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2266
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021052806
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1818
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021080914
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1877
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021092220
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163328/Red-Hat-Security-Advisory-2021-2575-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1637
来源:www.ibm.com
链接:https://www.ibm.com/support/pages/node/6520474
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2021-3520
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2555
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021063006
来源:access.redhat.com
链接:https://access.redhat.com/security/cve/cve-2021-3520
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3141
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163957/Red-Hat-Security-Advisory-2021-3361-01.html
受影响实体
暂无
补丁
- LZ4 输入验证错误漏洞的修复措施<!--2021-4-28-->
还没有评论,来说两句吧...