Heap-based buffer overflow in LZ4 - CVE-2019-17543
Published: November 4, 2019
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the LZ4_write32 when performing archiving operation with LZ4_compress_fast. A remote attacker can pass specially crafted input to the application, trigger heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
DataMosaix Private Cloud
Business Automation Insights
Netcool Operations Insight
Ansible Automation Platform
Red Hat Advanced Cluster Security for Kubernetes
lz4 (Alpine package)
liblz4-1
liblz4-1-debuginfo
lz4-debuginfo
lz4-debugsource
MySQL Server
IBM Qradar SIEM
IBM DataPower Gateway
Red Hat OpenShift Container Platform
SUSE Linux Enterprise Software Development Kit
Opensuse
Red Hat OpenShift Serverless
How to mitigate CVE-2019-17543
DataMosaix Private Cloud - update to 7.09
Netcool Operations Insight - update to 1.6.15
lz4 (Alpine package) - update to 1.9.1-r1
MySQL Server - addressed in versions 5.7.35, 8.0.26
IBM Qradar SIEM - update to 7.5.0 Update Pack 13 IF01
IBM DataPower Gateway - addressed in versions 10.5.0.19, 10.6.0.7
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.6, 25.0.0.0.3
Red Hat OpenShift Serverless - update to 1
liblz4-1 - update to 1.8.0-3.3.1
liblz4-1-debuginfo - update to 1.8.0-3.3.1
lz4-debuginfo - update to 1.8.0-3.3.1
lz4-debugsource - update to 1.8.0-3.3.1
Ansible Automation Platform - update to 2.5
Red Hat Advanced Cluster Security for Kubernetes - update to 4.7.5
Red Hat OpenShift Container Platform - update to 4.14.54
External References
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=15941
- https://github.com/lz4/lz4/compare/v1.9.1...v1.9.2
- https://github.com/lz4/lz4/issues/801
- https://github.com/lz4/lz4/pull/756
- https://github.com/lz4/lz4/pull/760
- https://lists.apache.org/thread.html/25015588b770d67470b7ba7ea49a305d6735dd7f00eabe7d50ec1e17@%3Cissues.arrow.apache.org%3E
- https://lists.apache.org/thread.html/793012683dc0fa6819b7c2560e6cf990811014c40c7d75412099c357@%3Cissues.arrow.apache.org%3E
- https://lists.apache.org/thread.html/9ff0606d16be2ab6a81619e1c9e23c3e251756638e36272c8c8b7fa3@%3Cissues.arrow.apache.org%3E
- https://lists.apache.org/thread.html/f0038c4fab2ee25aee849ebeff6b33b3aa89e07ccfb06b5c87b36316@%3Cissues.arrow.apache.org%3E
- https://lists.apache.org/thread.html/f506bc371d4a068d5d84d7361293568f61167d3a1c3e91f0def2d7d3@%3Cdev.arrow.apache.org%3E
Related Security Bulletins
- Buffer overflow in LZ4 archiver
- OpenSUSE Linux update for lz4
- OpenSUSE Linux update for lz4
- Heap-based buffer overflow in lz4 (Alpine package)
- Multiple vulnerabilities in MySQL Server
- SUSE update for lz4
- Multiple vulnerabilities in Rockwell Automation DataMosaix Private Cloud
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.7
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in IBM QRadar SIEM
- IBM DataPower Gateway update for LZ4
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in IBM Business Automation Insights
- Multiple vulnerabilities in Ansible Automation Platform 2.5 packages