CVE-2020-14315

A memory corruption vulnerability is present in bspatch as shipped in Colin Percival’s bsdiff tools version 4.3. Insufficient checks when handling external inputs allows an attacker to bypass the sanity checks in place and write out of a dynamically allocated buffer boundaries.
References
Link Resource
https://bugzilla.redhat.com/show_bug.cgi?id=1856747 Issue Tracking Third Party Advisory
https://www.openwall.com/lists/oss-security/2020/07/09/2 Mailing List Third Party Advisory
https://www.x41-dsec.de/lab/advisories/x41-2020-006-bspatch/ Exploit Third Party Advisory
Configurations

Configuration 1

cpe:2.3:a:daemonology:bsdiff:4.3:*:*:*:*:*:*:*

Information

Published : 2020-09-16 02:15

Updated : 2022-01-01 06:38


NVD link : CVE-2020-14315

Mitre link : CVE-2020-14315

Products Affected
No products.
CWE