CVE-2020-14315: Critical severity bsdiff4 vulnerability
A memory corruption vulnerability is present in bspatch as shipped in Colin Percival’s bsdiff tools version 4.3. Insufficient checks when handling external inputs allows an attacker to bypass the sanity checks in place and write out of a dynamically allocated buffer boundaries.
References: https://www.openwall.com/lists/oss-security/2020/07/09/2
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this memory corruption vulnerability?
The vulnerability ID for this memory corruption vulnerability is CVE-2020-14315.
What is the severity level of CVE-2020-14315?
The severity level of CVE-2020-14315 is critical.
Which software is affected by CVE-2020-14315?
The software affected by CVE-2020-14315 is Colin Percival’s bsdiff tools version 4.3.
How can an attacker exploit CVE-2020-14315?
An attacker can exploit CVE-2020-14315 by bypassing sanity checks and writing out of a dynamically allocated buffer boundaries.
Are there any references available for CVE-2020-14315?
Yes, references for CVE-2020-14315 are available at the following links: [Link 1](https://bugzilla.redhat.com/show_bug.cgi?id=1856747), [Link 2](https://www.openwall.com/lists/oss-security/2020/07/09/2), [Link 3](https://www.x41-dsec.de/lab/advisories/x41-2020-006-bspatch/).