-
-
Notifications
You must be signed in to change notification settings - Fork 221
/
CVE-2019-12410.yml
23 lines (23 loc) · 1009 Bytes
/
CVE-2019-12410.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
---
gem: red-arrow
cve: 2019-12410
ghsa: cjw4-2w9r-r8mv
url: https://lists.apache.org/thread.html/49f067b1c5fb7493d952580f0d2d032819ba351f7a78743c21126269@%3Cdev.arrow.apache.org%3E
title: Missing Initialization of Resource in Apache Arrow
date: 2022-05-24
description: |
While investigating UBSAN errors in https://github.com/apache/arrow/pull/5365
it was discovered Apache Arrow versions 0.12.0 to 0.14.1, left memory Array data
uninitialized when reading RLE null data from parquet. This affected the C++, Python,
Ruby and R implementations. The uninitialized memory could potentially be shared
if are transmitted over the wire (for instance with Flight) or persisted in the
streaming IPC and file formats.
cvss_v3: 7.5
unaffected_versions:
- "< 0.12.0"
patched_versions:
- ">= 0.15.1"
related:
url:
- https://lists.apache.org/thread.html/efd8bbf57427d3c303b5316d208a335f8d0c0dbe0dc4c87cfa995073@%3Cannounce.apache.org%3E
- http://www.openwall.com/lists/oss-security/2019/11/08/1