{ "document": { "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "description", "text": "A race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to write bytes out of bounds if an output buffer smaller than the recommended size was used.", "title": "Vulnerability Description" } ], "publisher": { "category": "other", "contact_details": "gdt@cpan.org", "name": "giterlizzi", "namespace": "https://github.com/giterlizzi/" }, "references": [ { "category": "self", "summary": "CPANSA-Sereal-Encoder-2019-11922-zstd JSON", "url": "https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2019/cpansa-sereal-encoder-2019-11922-zstd.json" }, { "category": "external", "summary": "https://www.facebook.com/security/advisories/cve-2019-11922", "url": "https://www.facebook.com/security/advisories/cve-2019-11922" }, { "category": "external", "summary": "https://github.com/facebook/zstd/pull/1404/commits/3e5cdf1b6a85843e991d7d10f6a2567c15580da0", "url": "https://github.com/facebook/zstd/pull/1404/commits/3e5cdf1b6a85843e991d7d10f6a2567c15580da0" }, { "category": "external", "summary": "http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00008.html", "url": "http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00008.html" }, { "category": "external", "summary": "http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00062.html", "url": "http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00062.html" }, { "category": "external", "summary": "https://usn.ubuntu.com/4108-1/", "url": "https://usn.ubuntu.com/4108-1/" }, { "category": "external", "summary": "http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00078.html", "url": "http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00078.html" }, { "category": "external", "summary": "https://www.oracle.com/security-alerts/cpuoct2020.html", "url": "https://www.oracle.com/security-alerts/cpuoct2020.html" }, { "category": "external", "summary": "CVE-2019-11922 (NVD)", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-11922" } ], "title": "Sereal-Encoder vulnerability", "tracking": { "current_release_date": "2019-07-25T00:00:00", "generator": { "engine": { "name": "CSAF Perl Toolkit", "version": "0.26" } }, "id": "CPANSA-Sereal-Encoder-2019-11922-zstd", "initial_release_date": "2019-07-25T00:00:00", "revision_history": [ { "date": "2019-07-25T00:00:00", "number": "1", "summary": "First release" } ], "status": "final", "version": "1" } }, "product_tree": { "branches": [ { "branches": [ { "category": "product_version_range", "name": "vers:cpan/>=4.001_001|<4.009_002", "product": { "name": "Sereal-Encoder greater than or equal 4.001_001 and less than 4.009_002", "product_id": "CSAFPID-0001", "product_identification_helper": { "purl": "pkg:cpan/Sereal-Encoder" } } } ], "category": "product_name", "name": "Sereal-Encoder" } ] }, "vulnerabilities": [ { "cve": "CVE-2019-11922", "cwe": { "id": "CWE-362", "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')" }, "notes": [ { "category": "description", "text": "A race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to write bytes out of bounds if an output buffer smaller than the recommended size was used.", "title": "Vulnerability Description" } ], "product_status": { "known_affected": [ "CSAFPID-0001" ] }, "scores": [ { "cvss_v2": { "baseScore": 6.8, "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P", "version": "2.0" }, "cvss_v3": { "baseScore": 8.1, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "CSAFPID-0001" ] } ] } ] }