VDB

DEBIAN-CVE-2022-4899

DEBIAN-CVE-2022-4899 PUBLISHED CVSS 7.5 HIGH

A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause buffer overrun.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Debian:14libzstd0, 0, 0
Debian:13libzstd0, 0, 0
Debian:11libzstd1.5.2+dfsg2, 1.5.2+dfsg2, 1.5.2+dfsg2
Debian:12libzstd0, 0, 0

Timeline

  • Mar 31, 2023 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›