{"id":"GHSA-9q5j-jm53-v7vr","aliases":["RUSTSEC-2022-0051"],"url":"https://o3.security/vulnerability/GHSA-9q5j-jm53-v7vr","summary":"lz4-sys vulnerable to memory corruption via issue in liblz4","details":"lz4-sys up to v1.9.3 bundles a version of liblz4 that is vulnerable to\n[CVE-2021-3520](https://nvd.nist.gov/vuln/detail/CVE-2021-3520).\n\nAttackers could craft a payload that triggers an integer overflow upon\ndecompression, causing an out-of-bounds write.\n\nThe flaw has been corrected in version v1.9.4 of liblz4, which is included\nin lz4-sys 1.9.4.\n","published":"2022-09-01T22:24:55Z","modified":"2023-11-08T04:18:03.475448Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"lz4-sys","fixedVersion":"1.9.4"}],"fix":{"url":"https://github.com/lz4/lz4/pull/972","label":"lz4/lz4#972"},"references":[{"type":"WEB","url":"https://github.com/lz4/lz4/pull/972"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2022-0051.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T04:18:03.475448Z"}}