CVE-2020-15904

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
22/07/2020
Last modified:
28/01/2023

Description

A buffer overflow in the patching routine of bsdiff4 before 1.2.0 allows an attacker to write to heap memory (beyond allocated bounds) via a crafted patch file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pypi:bsdiff4:*:*:*:*:*:*:*:* 1.2.0 (excluding)