CVE-2020-35963: High severity fluent bit by treasure data vulnerability
Published Jan 3, 2021
·Updated
flbgzipcompress in flbgzip.c in Fluent Bit before 1.6.4 has an out-of-bounds write because it does not use the correct calculation of the maximum gzip data-size expansion.
Affected Software
2 affected components
Treasuredata Fluent Bit<1.6.4
Linux Linux kernel
Remediation
Event History
Jan 3, 2021
CVE Published
via MITRE·06:15 PM
Data Sourced
via MITRE·06:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-35963?
CVE-2020-35963 is classified as a moderate severity vulnerability due to its potential for causing an out-of-bounds write.
2
How do I fix CVE-2020-35963?
To fix CVE-2020-35963, upgrade Fluent Bit to version 1.6.4 or later.
3
What software is affected by CVE-2020-35963?
CVE-2020-35963 affects Fluent Bit versions prior to 1.6.4.
4
What is the nature of the vulnerability in CVE-2020-35963?
The vulnerability in CVE-2020-35963 involves an out-of-bounds write caused by incorrect calculations in gzip data-size expansion.
5
Can CVE-2020-35963 impact Linux systems?
CVE-2020-35963 primarily affects the Fluent Bit application and does not directly impact the Linux kernel.