LZ4 through 1.10.0 allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact when the application processes untrusted LZ4 frames. For example, LZ4FcreateCDictadvanced in lib/lz4frame.c mishandles NULL checks.
{
"binaries": [
{
"binary_version": "1.9.2-2ubuntu0.20.04.1",
"binary_name": "liblz4-1"
},
{
"binary_version": "1.9.2-2ubuntu0.20.04.1",
"binary_name": "liblz4-dev"
},
{
"binary_version": "1.9.2-2ubuntu0.20.04.1",
"binary_name": "liblz4-tool"
},
{
"binary_version": "1.9.2-2ubuntu0.20.04.1",
"binary_name": "lz4"
}
]
}{
"binaries": [
{
"binary_version": "1.9.3-2build2",
"binary_name": "liblz4-1"
},
{
"binary_version": "1.9.3-2build2",
"binary_name": "liblz4-dev"
},
{
"binary_version": "1.9.3-2build2",
"binary_name": "liblz4-tool"
},
{
"binary_version": "1.9.3-2build2",
"binary_name": "lz4"
}
]
}{
"binaries": [
{
"binary_version": "1.9.4-1build1.1",
"binary_name": "liblz4-1"
},
{
"binary_version": "1.9.4-1build1.1",
"binary_name": "liblz4-dev"
},
{
"binary_version": "1.9.4-1build1.1",
"binary_name": "liblz4-tool"
},
{
"binary_version": "1.9.4-1build1.1",
"binary_name": "lz4"
}
]
}