c-blosc2 ndlz8x8.c ndlz8_decompress heap-based overflow
Published Apr 2, 2024
9.8
CRITICALCVSS 3.1
EPSS 1.35%
Description
A vulnerability, which was classified as critical, was found in c-blosc2 up to 2.13.2. Affected is the function ndlz8_decompress of the file /src/c-blosc2/plugins/codecs/ndlz/ndlz8x8.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.14.3 is able to address this issue. It is recommended to upgrade the affected component. VDB-259050 is the identifier assigned to this vulnerability.
Affected products
- Vendor n/a Product C-Blosc2 Defaultn/a
- Version 2.13.0StatusaffectedConstraints-
- Version 2.13.1StatusaffectedConstraints-
- Version 2.13.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| n/a | C-Blosc2 | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://drive.google.com/drive/folders/1T1k3UeS09m65LjVXExUuZfedNQPWQWCo?usp=sharing exploitProduct
- https://github.com/Blosc/c-blosc2/releases/tag/v2.14.3 patchRelease Notes
- https://vuldb.com/?ctiid.259050 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.259050 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.304556 third-party-advisoryExploitVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://drive.google.com/drive/folders/1T1k3UeS09m65LjVXExUuZfedNQPWQWCo?usp=sharing | exploitProduct | |
| https://github.com/Blosc/c-blosc2/releases/tag/v2.14.3 | patchRelease Notes | |
| https://vuldb.com/?ctiid.259050 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.259050 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.304556 | third-party-advisoryExploitVDB Entry |
Change history (0)
No recorded changes yet.