Logo
vulnerabilityCVE-2020-14315
Name
CVE-2020-14315
Source
NVD ( link)Debian ( link)
Description
A memory corruption vulnerability is present in bspatch as shipped in Colin Percival’s bsdiff tools version 4.3. Insufficient checks when handling external inputs allows an attacker to bypass the sanity checks in place and write out of a dynamically allocated buffer boundaries.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
bsdiff
Patched

Vulnerability Ratings#


9.8
CVSSv31
7.5
CVSSv2

Others affected component#


Name
Project
Project Version
Version
Status
openwrt
master
4.3-r2
Patched

Resolved with patches#


bsdiff (openwrt:master)

#
Title
Author
Resolve
1
Patch #1
Unknown
CVE-2020-14315

bsdiff (openwrt:openwrt-25.12)

#
Title
Author
Resolve
1
Patch #1
Unknown
CVE-2020-14315