GHSA-55g7-9cwv-5qfv
HIGHCVE-2023-43642snappy-java is a data compression library in Java. Its SnappyInputStream was found to be vulnerable to Denial of Service (DoS) attacks when decompressing data with a too-large chunk size. Due to missing upper bound check on chunk length, an unrecoverable fatal error can occur.
- Affected
- <= 1.1.10.3
- Fixed in
- 1.1.10.4
- Weakness
- CWE-770
- Published
- 2023-09-25
- Source
- github