Uploaded image for project: 'Kudu'
  1. Kudu
  2. KUDU-3156

Whether the CVE-2019-17543 vulnerability of lz affects kudu

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Information Provided
    • 1.8.0
    • n/a
    • None
    • None

    Description

      LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize), affecting applications that call LZ4_compress_fast with a large input. (This issue can also lead to data corruption.) NOTE: the vendor states "only a few specific / uncommon usages of the API are at risk."      

      Whether the CVE-2019-17543 vulnerability of lz affects kudu? if yes, what is the impact?

      Attachments

        Activity

          People

            Unassigned Unassigned
            yejiabao_h yejiabao_h
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: