Buffer overflow in Zstandard - CVE-2022-4899

 

Buffer overflow in Zstandard - CVE-2022-4899

Published: March 30, 2023


Vulnerability identifier: #VU74201
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-4899
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in util.c when processing empty arguments in the command line tool. A remote attacker can pass an empty string as an argument, trigger buffer underflow and crash the application.


Affected software

Zstandard
Amazon Linux AMI
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Oracle Solaris
Basesystem Module
openSUSE Leap
openEuler
Fedora
Guardium Data Security Center (GDSC)
ObjectScale
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Oracle SD-WAN Edge
MySQL Server
MySQL Connectors
MySQL Cluster
mecab
zstd-debugsource
libzstd1
libzstd1-debuginfo
zstd
zstd-debuginfo
libzstd1-32bit
libzstd1-32bit-debuginfo
libzstd-devel
zstd-devel
zstd-help
libzstd-devel-32bit
libzstd-devel-static
mingw-zstd
mecab-ipadic
mecab-ipadic-EUCJP
community-mysql
rh-mysql80-mysql (Red Hat package)
mysql (Red Hat package)
mysql
mysql-common
mysql-devel
mysql-errmsg
mysql-libs
mysql-server
mysql-test
AMQ Streams

How to mitigate CVE-2022-4899

Install updates from vendor's website.

Zstandard - update to 1.5.4
Guardium Data Security Center (GDSC) - update to 3.6.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.2.0
MySQL Server - update to 8.0.34
MySQL Cluster - update to 8.0.34
mecab - update to 0.996-2
ObjectScale - update to 1.4.0
zstd-debugsource - addressed in versions 1.4.4-150000.1.9.1, 1.5.0-150400.3.3.1
libzstd1 - addressed in versions 1.4.4-150000.1.9.1, 1.5.0-150400.3.3.1
libzstd1-debuginfo - addressed in versions 1.4.4-150000.1.9.1, 1.5.0-150400.3.3.1
zstd - addressed in versions 1.4.4-150000.1.9.1, 1.5.0-150400.3.3.1
zstd-debuginfo - addressed in versions 1.4.4-150000.1.9.1, 1.5.0-150400.3.3.1
libzstd1-32bit - addressed in versions 1.4.4-150000.1.9.1, 1.5.0-150400.3.3.1
libzstd1-32bit-debuginfo - addressed in versions 1.4.4-150000.1.9.1, 1.5.0-150400.3.3.1
libzstd-devel - addressed in versions 1.4.4-150000.1.9.1, 1.5.0-150400.3.3.1
zstd-debuginfo - update to 1.5.0-4
zstd-debugsource - update to 1.5.0-4
zstd-devel - update to 1.5.0-4
zstd - update to 1.5.0-4
zstd-help - update to 1.5.0-4
libzstd-devel-32bit - update to 1.5.0-150400.3.3.1
libzstd-devel-static - update to 1.5.0-150400.3.3.1
zstd - update to 1.5.2-1
mingw-zstd - addressed in versions 1.5.4-1.fc36, 1.5.4-1.fc37, 1.5.4-1.fc38
AMQ Streams - update to 2.7.0
mecab-ipadic - update to 2.7.0.20070801-16.0.1
mecab-ipadic-EUCJP - update to 2.7.0.20070801-16.0.1
community-mysql - addressed in versions 8.0.34-2.fc37, 8.0.34-2.fc38, 8.0.34-2.fc39
rh-mysql80-mysql (Red Hat package) - update to 8.0.36-1.el7
mysql (Red Hat package) - update to 8.0.36-1.el9_3
mysql - update to 8.0.36-1.0.1
mysql-common - update to 8.0.36-1.0.1
mysql-devel - update to 8.0.36-1.0.1
mysql-errmsg - update to 8.0.36-1.0.1
mysql-libs - update to 8.0.36-1.0.1
mysql-server - update to 8.0.36-1.0.1
mysql-test - update to 8.0.36-1.0.1
mysql - addressed in versions 8.0-3720230907003352.9e842022, 8.0-3820230907003352.75741a8b

External References

Related Security Bulletins