Skip to main content
Version: latest

CVE-2019-17543

CVE Details

CVE-2019-17543

Last Update

08/16/2024

NIST CVE Summary

LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize), affecting applications that call LZ4_compress_fast with a large input. (This issue can also lead to data corruption.) NOTE: the vendor states "only a few specific / uncommon usages of the API are at risk."

Our Official Summary

Waiting on a fix from third party mongodb vendor

CVE Severity

8.1

Status

Ongoing

Affected Products & Versions

  • Palette VerteX 4.4.14

Revision History

  • 1.0 08/16/2024 Initial Publication
  • 2.0 08/17/2024 Added palette VerteX 4.4.14 to Affected Products