CVE Published: 27/12/2022 |
CVE Updated: 06/08/2024 |
CVE Year: 2014 Source: Go |
Vendor: github.com/cloudflare/golz4 |
Product: github.com/cloudflare/golz4 Status : PUBLISHED
CVE-2014-125026 Description
LZ4 bindings use a deprecated C API that is vulnerable to memory corruption, which could lead to arbitrary code execution if called with untrusted user input.