Vulnerability Report: GO-2020-0022
- CVE-2014-125026, GHSA-4wp2-8rm2-jgmh
- Affects: github.com/cloudflare/golz4
- Published: Apr 14, 2021
- Modified: May 20, 2024
LZ4 bindings use a deprecated C API that is vulnerable to memory corruption, which could lead to arbitrary code execution if called with untrusted user input.
Affected Packages
-
PathGo VersionsSymbols
-
before v0.0.0-20140711154735-199f5f787806
Aliases
References
- https://github.com/cloudflare/golz4/commit/199f5f7878062ca17a98e079f2dbe1205e2ed898
- https://github.com/cloudflare/golz4/issues/5
- https://vuln.go.dev/ID/GO-2020-0022.json
Credits
- Yann Collet
Feedback
See anything missing or incorrect?
Suggest an edit to this report.