CVE-2020-29367: Buffer Overflow
Published Nov 27, 2020
·Updated
blosc2.c in Blosc C-Blosc2 through 2.0.0.beta.5 has a heap-based buffer overflow when there is a lack of space to write compressed data.
Affected Software
19 affected componentsFixes available
C-blosc2 Project C-blosc2=2.0.0-a2
C-blosc2 Project C-blosc2=2.0.0-a3
C-blosc2 Project C-blosc2=2.0.0-a4
C-blosc2 Project C-blosc2=2.0.0-a5
C-blosc2 Project C-blosc2=2.0.0-beta1
C-blosc2 Project C-blosc2=2.0.0-beta2
C-blosc2 Project C-blosc2=2.0.0-beta3
C-blosc2 Project C-blosc2=2.0.0-beta4
C-blosc2 Project C-blosc2=2.0.0-beta5
blosc C-Blosc2=2.0.0-alpha2
blosc C-Blosc2=2.0.0-alpha3
blosc C-Blosc2=2.0.0-alpha4
blosc C-Blosc2=2.0.0-alpha5
blosc C-Blosc2=2.0.0-beta1
blosc C-Blosc2=2.0.0-beta2
blosc C-Blosc2=2.0.0-beta3
blosc C-Blosc2=2.0.0-beta4
blosc C-Blosc2=2.0.0-beta5
pip/blosc2<0.1.7
0.1.7
Remediation
Event History
Nov 27, 2020
CVE Published
via MITRE·07:07 PM
Data Sourced
via MITRE·07:07 PM
Description
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 24, 2022
Advisory Published
via GitHub·05:35 PM
Frequently Asked Questions
1
What is the severity of CVE-2020-29367?
CVE-2020-29367 has a medium severity rating due to the potential for a heap-based buffer overflow.
2
How do I fix CVE-2020-29367?
To fix CVE-2020-29367, upgrade to Blosc2 version 0.1.7 or higher.
3
Which versions of Blosc2 are affected by CVE-2020-29367?
CVE-2020-29367 affects Blosc2 versions 2.0.0-a2, 2.0.0-a3, 2.0.0-a4, 2.0.0-a5, 2.0.0-beta1, 2.0.0-beta2, 2.0.0-beta3, 2.0.0-beta4, and 2.0.0-beta5.
4
What type of vulnerability is CVE-2020-29367?
CVE-2020-29367 is a heap-based buffer overflow vulnerability.
5
Where can I find more information about CVE-2020-29367?
Additional details about CVE-2020-29367 can be found in the official security advisories and issue tracking systems.