Logo
componentzstd
Name
zstd
Version
1.5.2
Type
library
Description
Zstandard - Fast real-time compression algorithm
Licenses
BSD-3-Clause | GPL-2.0-only
PURL
-
CPE
cpe:2.3:*:facebook:zstandard:1.5.2:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
master
1.5.7
scarthgap
1.5.5

Patches#


#
Title
Author
Resolve
1
Disallow empty output directory
Elliot Gorokhovsky <embg@fb.com>
CVE-2022-4899
2
Fix buffer underflow for null dir1
Elliot Gorokhovsky <embg@fb.com>
CVE-2022-4899

Vulnerabilities#


Name
Analysis
Description
Patched
A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause buffer overrun.