Heap-based buffer overflow in LZ4 - CVE-2019-17543

 

Heap-based buffer overflow in LZ4 - CVE-2019-17543

Published: November 4, 2019


Vulnerability identifier: #VU22494
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-17543
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within the LZ4_write32 when performing archiving operation with LZ4_compress_fast. A remote attacker can pass specially crafted input to the application, trigger heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

LZ4
DataMosaix Private Cloud
Business Automation Insights
Netcool Operations Insight
Ansible Automation Platform
Red Hat Advanced Cluster Security for Kubernetes
lz4 (Alpine package)
liblz4-1
liblz4-1-debuginfo
lz4-debuginfo
lz4-debugsource
MySQL Server
IBM Qradar SIEM
IBM DataPower Gateway
Red Hat OpenShift Container Platform
SUSE Linux Enterprise Software Development Kit
Opensuse
Red Hat OpenShift Serverless

How to mitigate CVE-2019-17543

Install updates from vendor's website.

LZ4 - update to 1.9.2
DataMosaix Private Cloud - update to 7.09
Netcool Operations Insight - update to 1.6.15
lz4 (Alpine package) - update to 1.9.1-r1
MySQL Server - addressed in versions 5.7.35, 8.0.26
IBM Qradar SIEM - update to 7.5.0 Update Pack 13 IF01
IBM DataPower Gateway - addressed in versions 10.5.0.19, 10.6.0.7
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.6, 25.0.0.0.3
Red Hat OpenShift Serverless - update to 1
liblz4-1 - update to 1.8.0-3.3.1
liblz4-1-debuginfo - update to 1.8.0-3.3.1
lz4-debuginfo - update to 1.8.0-3.3.1
lz4-debugsource - update to 1.8.0-3.3.1
Ansible Automation Platform - update to 2.5
Red Hat Advanced Cluster Security for Kubernetes - update to 4.7.5
Red Hat OpenShift Container Platform - update to 4.14.54

External References

Related Security Bulletins