CVE-2019-11922
Published: 25 July 2019
A race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to write bytes out of bounds if an output buffer smaller than the recommended size was used.
Priority
Status
Package | Release | Status |
---|---|---|
libzstd Launchpad, Ubuntu, Debian |
groovy |
Not vulnerable
(1.3.8+dfsg-2)
|
jammy |
Not vulnerable
(1.3.8+dfsg-2)
|
|
xenial |
Released
(1.3.1+dfsg-1~ubuntu0.16.04.1+esm2)
Available with Ubuntu Pro or Ubuntu Pro (Infra-only) |
|
bionic |
Released
(1.3.3+dfsg-2ubuntu1.1)
|
|
disco |
Not vulnerable
(1.3.8+dfsg-2)
|
|
eoan |
Not vulnerable
(1.3.8+dfsg-2)
|
|
focal |
Not vulnerable
(1.3.8+dfsg-2)
|
|
hirsute |
Not vulnerable
(1.3.8+dfsg-2)
|
|
impish |
Not vulnerable
(1.3.8+dfsg-2)
|
|
kinetic |
Not vulnerable
(1.3.8+dfsg-2)
|
|
trusty |
Does not exist
|
|
upstream |
Released
(1.3.8+dfsg-2)
|
|
Patches: upstream: https://github.com/facebook/zstd/commit/3e5cdf1b6a85843e991d7d10f6a2567c15580da0 |
Severity score breakdown
Parameter | Value |
---|---|
Base score | 8.1 |
Attack vector | Network |
Attack complexity | High |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | High |
Availability impact | High |
Vector | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11922
- https://github.com/facebook/zstd/pull/1404/commits/3e5cdf1b6a85843e991d7d10f6a2567c15580da0
- https://www.facebook.com/security/advisories/cve-2019-11922
- https://ubuntu.com/security/notices/USN-4108-1
- https://ubuntu.com/security/notices/USN-5593-1
- NVD
- Launchpad
- Debian