cve 2022 4899

  1. CVE-2022-4899: Zstd CLI Empty String Bug and Patch

    A subtle mistake in zstd’s argument-handling code allows a trivial input — an empty string passed to certain command-line options — to produce a buffer overrun that can crash or disable processes that use the zstd CLI. The bug, tracked as CVE-2022-4899, affects the zstd command-line utility...