CVE-2021-3520

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
02/06/2021
Last modified:
06/06/2024

Description

There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lz4_project:lz4:*:*:*:*:*:*:*:* 1.8.3 (including) 1.9.4 (excluding)
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.14.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:*
cpe:2.3:a:splunk:universal_forwarder:*:*:*:*:*:*:*:* 8.2.0 (including) 8.2.12 (excluding)
cpe:2.3:a:splunk:universal_forwarder:*:*:*:*:*:*:*:* 9.0.0 (including) 9.0.6 (excluding)
cpe:2.3:a:splunk:universal_forwarder:9.1.0:*:*:*:*:*:*:*