CVE-2020-15904: Buffer Overflow
Published Jul 22, 2020
·Updated
A buffer overflow in the patching routine of bsdiff4 before 1.2.0 allows an attacker to write to heap memory (beyond allocated bounds) via a crafted patch file.
Affected Software
2 affected componentsFixes available
pip/bsdiff4<1.2.0
1.2.0
PyPI Bsdiff4<1.2.0
Remediation
Event History
Jul 22, 2020
CVE Published
via MITRE·10:25 PM
Data Sourced
via MITRE·10:25 PM
Description
May 24, 2022
Advisory Published
via GitHub·05:24 PM
Frequently Asked Questions
1
What is the severity of CVE-2020-15904?
CVE-2020-15904 is classified as a high severity vulnerability due to the potential for remote code execution through a buffer overflow.
2
How do I fix CVE-2020-15904?
To fix CVE-2020-15904, upgrade bsdiff4 to version 1.2.0 or later.
3
What impact does CVE-2020-15904 have on affected systems?
CVE-2020-15904 allows an attacker to write to heap memory, which could lead to arbitrary code execution on affected systems.
4
Which versions of bsdiff4 are vulnerable to CVE-2020-15904?
All versions of bsdiff4 prior to 1.2.0 are vulnerable to CVE-2020-15904.
5
Is there a workaround for CVE-2020-15904 if I cannot upgrade bsdiff4?
There is no official workaround for CVE-2020-15904; upgrading to the fixed version is recommended.