High severity7.8OSV Advisory· Published May 26, 2018· Updated Jun 17, 2026
CVE-2018-11498
CVE-2018-11498
Description
In Lizard v1.0 and LZ5 v2.0 (the prior release, before the product was renamed), there is an unchecked buffer size during a memcpy in the Lizard_decompress_LIZv1 function (lib/lizard_decompress_liz.h). Remote attackers can leverage this vulnerability to cause a denial of service via a crafted input file, as well as achieve remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- cpe:2.3:a:lizard_project:lizard:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:lizard_project:lz5:2.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- github.com/inikep/lizard/issues/16nvdThird Party Advisory
News mentions
0No linked articles in our index yet.