Vulnerability Description
In Lizard v1.0 and LZ5 v2.0 (the prior release, before the product was renamed), there is an unchecked buffer size during a memcpy in the Lizard_decompress_LIZv1 function (lib/lizard_decompress_liz.h). Remote attackers can leverage this vulnerability to cause a denial of service via a crafted input file, as well as achieve remote code execution.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lizard Project | Lizard | 1.0 |
| Lizard Project | Lz5 | 2.0 |
Related Weaknesses (CWE)
References
- https://github.com/inikep/lizard/issues/16Third Party Advisory
- https://github.com/inikep/lizard/issues/16Third Party Advisory
FAQ
What is CVE-2018-11498?
CVE-2018-11498 is a vulnerability with a CVSS score of 7.8 (HIGH). In Lizard v1.0 and LZ5 v2.0 (the prior release, before the product was renamed), there is an unchecked buffer size during a memcpy in the Lizard_decompress_LIZv1 function (lib/lizard_decompress_liz.h)...
How severe is CVE-2018-11498?
CVE-2018-11498 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-11498?
Check the references section above for vendor advisories and patch information. Affected products include: Lizard Project Lizard, Lizard Project Lz5.