Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2022-4899

Published: March 31, 2023Last modified: September 16, 2023

Description

A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause buffer overrun.

Severity score breakdown

ParameterValue
Base score7.5
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSzstdNot affected (1.5.5-r0)
StreamzstdNot affected (1.5.5-r5)

References

ON THIS PAGE