Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Question concerning CVE-2014-4715 #818

Closed
Satann opened this issue Dec 4, 2019 · 2 comments
Closed

Question concerning CVE-2014-4715 #818

Satann opened this issue Dec 4, 2019 · 2 comments
Labels

Comments

@Satann
Copy link

Satann commented Dec 4, 2019

Hi,
I am just looking into CVE-2014-4715 [1], specifically I am trying to verify if the issue is present since 2014.
the topic concerns of versions before 1.1.9. so i search the issues and release notes of v1.1.9.
but i can't find some references proving the CVE-2014-4715 be solved.
so please help me to check it, thanks very much.

[0] https://nvd.nist.gov/vuln/detail/CVE-2014-4715

@Cyan4973
Copy link
Member

Cyan4973 commented Dec 4, 2019

This was fixed at release r119 (the versioning system used to be different back then),
available at : https://github.com/lz4/lz4/releases/tag/r119 ,
released Jul 2, 2014 .

The corresponding library lz4.h actually identifies itself as v1.2.0.

@Satann
Copy link
Author

Satann commented Dec 4, 2019

thank you very much, yan.
yes, from the release tag i find the commit solving this vulnerability : 140e6e7
now i can go on with my work!
best regards.

@Satann Satann closed this as completed Dec 4, 2019
buildroot-auto-update pushed a commit to buildroot/buildroot that referenced this issue Mar 28, 2020
CVE-2014-4715 is misclassified (by our CVE tracker) as affecting
version 1.9.2, while in fact this issue has been fixed since lz4-r130:
lz4/lz4@140e6e7

See lz4/lz4#818

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants