← Back

CVE-2020-8927

nvd nist
Published: Sep 15, 2020Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Exploitability: 3.9 / Impact: 2.5
Source: NVD

Description

A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the "streaming" API as opposed to the "one-shot" API, and impose chunk size limits.

Affected (21)

Products: Google: Brotli · Debian: Debian Linux · Fedoraproject: Fedora · +3 more
Show all products
1 product
Brotli
1 product
Debian Linux
1 product
Fedora
1 product
Ubuntu Linux
1 product
Leap
5 products
.net
.net Core
Powershell
Visual Studio 2019
Visual Studio 2022
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.0.8
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 9.0
Configuration C
6 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 31
Version 32
Version 33
Version 34
Version 35
Version 36
Configuration D
3 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 16.04
Version 18.04
Version 20.04
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 15.2
Configuration F
8 vulnerable
Vulnerable SoftwareAffected Versions
From 5.0 to 5.0.14
From 3.1 to 3.1.22
Microsoft
From 7.0 to 7.0.9
From 7.1 to 7.1.6
From 7.2 to 7.2.2
From 16.0 to 16.11
Microsoft
From 17.0 to 17.0.7
Version 17.1

References (28)

Source: cve-coordination@google.com
Mailing ListThird Party Advisory
Source: cve-coordination@google.com
Release NotesThird Party Advisory
Source: cve-coordination@google.com
Mailing ListThird Party Advisory
Source: cve-coordination@google.com
Third Party Advisory
Source: cve-coordination@google.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.