VDB
Sign up
CRITICAL9.8

GHSA-4wp2-8rm2-jgmh

LZ4 vulnerable to Out-of-bounds Write

Quick fix

GHSA-4wp2-8rm2-jgmh — github.com/cloudflare/golz4: upgrade to the fixed version with the command below.

go get github.com/cloudflare/golz4@v0.0.0-20140711154735-199f5f787806

Details

LZ4 bindings use a deprecated C API that is vulnerable to memory corruption, which could lead to arbitrary code execution if called with untrusted user input.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/cloudflare/golz4
Introduced in: 0Fixed in: 0.0.0-20140711154735-199f5f787806
Fixgo get github.com/cloudflare/golz4@v0.0.0-20140711154735-199f5f787806

References