A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause buffer overrun.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/facebook/zstd(SwiftURL) | 0 | 1.5.4 | N/A |
| zstd(PyPI) | 0 | 1.5.4.0 | N/A |
CVSS Metrics