lz4-sys
Activity
- Latest release
- 1y ago
- Total releases
- 13
- Cadence
- ~4 months
- Last 12 months
- 0
Details
- License
- MIT
- First release
- Nov 26, 2016
| Version | Released | |
|---|---|---|
1.11.1+lz4-1.10.0
unknown
|
1.11.1+lz4-1.10.0
unknown
Dependencies (2)
|
|
1.11.0
unknown
|
1.11.0
unknown
Dependencies (2)
|
|
1.10.0
unknown
|
1.10.0
unknown
Dependencies (2)
|
|
1.9.5
unknown
|
1.9.5
unknown
Dependencies (2)
|
|
1.9.4
unknown
|
1.9.4
unknown
Dependencies (2)
|
|
1.9.3
unknown
1 CVE
GHSA-9q5j-jm53-v7vr
RUSTSEC-2022-0051
Sep 01, 2022
lz4-sys vulnerable to memory corruption via issue in liblz4
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lz4-sys up to v1.9.3 bundles a version of liblz4 that is vulnerable to CVE-2021-3520. Attackers could craft a payload that triggers an integer overflow upon decompression, causing an out-of-bounds write. The flaw has been corrected in version v1.9.4 of liblz4, which is included in lz4-sys 1.9.4. Fixed in
1.9.4
References Updated Nov 08, 2023 · Source: OSV.dev |
1.9.3
unknown
Dependencies (2)
|
|
1.9.2
unknown
1 CVE
GHSA-9q5j-jm53-v7vr
RUSTSEC-2022-0051
Sep 01, 2022
lz4-sys vulnerable to memory corruption via issue in liblz4
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lz4-sys up to v1.9.3 bundles a version of liblz4 that is vulnerable to CVE-2021-3520. Attackers could craft a payload that triggers an integer overflow upon decompression, causing an out-of-bounds write. The flaw has been corrected in version v1.9.4 of liblz4, which is included in lz4-sys 1.9.4. Fixed in
1.9.4
References Updated Nov 08, 2023 · Source: OSV.dev |
1.9.2
unknown
Dependencies (2)
|
|
1.8.3
unknown
1 CVE
GHSA-9q5j-jm53-v7vr
RUSTSEC-2022-0051
Sep 01, 2022
lz4-sys vulnerable to memory corruption via issue in liblz4
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lz4-sys up to v1.9.3 bundles a version of liblz4 that is vulnerable to CVE-2021-3520. Attackers could craft a payload that triggers an integer overflow upon decompression, causing an out-of-bounds write. The flaw has been corrected in version v1.9.4 of liblz4, which is included in lz4-sys 1.9.4. Fixed in
1.9.4
References Updated Nov 08, 2023 · Source: OSV.dev |
1.8.3
unknown
Dependencies (2)
|
|
1.8.2
unknown
1 CVE
GHSA-9q5j-jm53-v7vr
RUSTSEC-2022-0051
Sep 01, 2022
lz4-sys vulnerable to memory corruption via issue in liblz4
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lz4-sys up to v1.9.3 bundles a version of liblz4 that is vulnerable to CVE-2021-3520. Attackers could craft a payload that triggers an integer overflow upon decompression, causing an out-of-bounds write. The flaw has been corrected in version v1.9.4 of liblz4, which is included in lz4-sys 1.9.4. Fixed in
1.9.4
References Updated Nov 08, 2023 · Source: OSV.dev |
1.8.2
unknown
Dependencies (2)
|
|
1.8.0
unknown
1 CVE
GHSA-9q5j-jm53-v7vr
RUSTSEC-2022-0051
Sep 01, 2022
lz4-sys vulnerable to memory corruption via issue in liblz4
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lz4-sys up to v1.9.3 bundles a version of liblz4 that is vulnerable to CVE-2021-3520. Attackers could craft a payload that triggers an integer overflow upon decompression, causing an out-of-bounds write. The flaw has been corrected in version v1.9.4 of liblz4, which is included in lz4-sys 1.9.4. Fixed in
1.9.4
References Updated Nov 08, 2023 · Source: OSV.dev |
1.8.0
unknown
Dependencies (2)
|
|
1.7.5
unknown
1 CVE
GHSA-9q5j-jm53-v7vr
RUSTSEC-2022-0051
Sep 01, 2022
lz4-sys vulnerable to memory corruption via issue in liblz4
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lz4-sys up to v1.9.3 bundles a version of liblz4 that is vulnerable to CVE-2021-3520. Attackers could craft a payload that triggers an integer overflow upon decompression, causing an out-of-bounds write. The flaw has been corrected in version v1.9.4 of liblz4, which is included in lz4-sys 1.9.4. Fixed in
1.9.4
References Updated Nov 08, 2023 · Source: OSV.dev |
1.7.5
unknown
Dependencies (2)
|
|
1.0.1+1.7.5
unknown
1 CVE
GHSA-9q5j-jm53-v7vr
RUSTSEC-2022-0051
Sep 01, 2022
lz4-sys vulnerable to memory corruption via issue in liblz4
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lz4-sys up to v1.9.3 bundles a version of liblz4 that is vulnerable to CVE-2021-3520. Attackers could craft a payload that triggers an integer overflow upon decompression, causing an out-of-bounds write. The flaw has been corrected in version v1.9.4 of liblz4, which is included in lz4-sys 1.9.4. Fixed in
1.9.4
References Updated Nov 08, 2023 · Source: OSV.dev |
1.0.1+1.7.5
unknown
Dependencies (2)
|
|
1.0.1+1.7.3
unknown
1 CVE
GHSA-9q5j-jm53-v7vr
RUSTSEC-2022-0051
Sep 01, 2022
lz4-sys vulnerable to memory corruption via issue in liblz4
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lz4-sys up to v1.9.3 bundles a version of liblz4 that is vulnerable to CVE-2021-3520. Attackers could craft a payload that triggers an integer overflow upon decompression, causing an out-of-bounds write. The flaw has been corrected in version v1.9.4 of liblz4, which is included in lz4-sys 1.9.4. Fixed in
1.9.4
References Updated Nov 08, 2023 · Source: OSV.dev |
1.0.1+1.7.3
unknown
Dependencies (2)
|