Logo
componentbsdiff
Name
bsdiff
Version
4.3-r2
Type
library
Description
-
Licenses
-
PURL
-
CPE
cpe:2.3:a:daemonology:bsdiff:4.3:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
openwrt-25.12
4.3-r2

Patches#


#
Title
Author
Resolve
1
Patch #1
Unknown
CVE-2020-14315
2
Patch #2
Unknown
3
CVE-2014-9862 - check for a negative value on numbers of bytes
The FreeBSD Project
CVE-2014-9862

Vulnerabilities#


Name
Analysis
Description
Patched
A memory corruption vulnerability is present in bspatch as shipped in Colin Percival’s bsdiff tools version 4.3. Insufficient checks when handling external inputs allows an attacker to bypass the sanity checks in place and write out of a dynamically allocated buffer boundaries.
Patched
Integer signedness error in bspatch.c in bspatch in bsdiff, as used in Apple OS X before 10.11.6 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via a crafted patch file.