CRITICAL9.8
GHSA-4wp2-8rm2-jgmh
LZ4 vulnerable to Out-of-bounds Write
Quick fix
GHSA-4wp2-8rm2-jgmh — github.com/cloudflare/golz4: upgrade to the fixed version with the command below.
go get github.com/cloudflare/golz4@v0.0.0-20140711154735-199f5f787806Details
LZ4 bindings use a deprecated C API that is vulnerable to memory corruption, which could lead to arbitrary code execution if called with untrusted user input.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/cloudflare/golz4
Introduced in:
0Fixed in: 0.0.0-20140711154735-199f5f787806Fix
go get github.com/cloudflare/golz4@v0.0.0-20140711154735-199f5f787806