Vulnerabilities > CVE-2014-125026 - Out-of-bounds Write vulnerability in Cloudflare Golz4
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
LZ4 bindings use a deprecated C API that is vulnerable to memory corruption, which could lead to arbitrary code execution if called with untrusted user input.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Common Weakness Enumeration (CWE)
References
- https://github.com/cloudflare/golz4/commit/199f5f7878062ca17a98e079f2dbe1205e2ed898
- https://github.com/cloudflare/golz4/commit/199f5f7878062ca17a98e079f2dbe1205e2ed898
- https://github.com/cloudflare/golz4/issues/5
- https://github.com/cloudflare/golz4/issues/5
- https://pkg.go.dev/vuln/GO-2020-0022
- https://pkg.go.dev/vuln/GO-2020-0022