CVE Published: 08/11/2019 |
CVE Updated: 04/08/2024 |
CVE Year: 2019 Source: apache |
Vendor: Apache Software Foundation |
Product: Apache Arrow Status : PUBLISHED
CVE-2019-12410 Description
While investigating UBSAN errors in https://github.com/apache/arrow/pull/5365 it was discovered Apache Arrow versions 0.12.0 to 0.14.1, left memory Array data uninitialized when reading RLE null data from parquet. This affected the C++, Python, Ruby and R implementations. The uninitialized memory could potentially be shared if are transmitted over the wire (for instance with Flight) or persisted in the streaming IPC and file formats.