{"id":"GHSA-f8m3-jpxr-hm5x","summary":"bsdiff4 out-of-bounds write via patch file","details":"A buffer overflow in the patching routine of bsdiff4 before 1.2.0 allows an attacker to write to heap memory (beyond allocated bounds) via a crafted patch file.","aliases":["CVE-2020-15904","PYSEC-2020-30"],"modified":"2024-09-06T16:00:45.511962Z","published":"2022-05-24T17:24:16Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-02-23T20:37:09Z","nvd_published_at":"2020-07-22T23:15:00Z","cwe_ids":["CWE-787"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-15904"},{"type":"WEB","url":"https://github.com/ilanschnell/bsdiff4/commit/49a4cee2feef7deaf9d89e5e793a8824930284d7"},{"type":"PACKAGE","url":"https://github.com/ilanschnell/bsdiff4"},{"type":"WEB","url":"https://github.com/ilanschnell/bsdiff4/blob/9a84c2ee01f5ba0742d18c9f3b3d5244ae7fb302/CHANGELOG.txt#L30-L31"},{"type":"WEB","url":"https://github.com/ilanschnell/bsdiff4/blob/master/CHANGELOG.txt"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/bsdiff4/PYSEC-2020-30.yaml"}],"affected":[{"package":{"name":"bsdiff4","ecosystem":"PyPI","purl":"pkg:pypi/bsdiff4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.0"}]}],"versions":["1.0.0","1.0.1","1.1.0","1.1.1","1.1.2","1.1.3","1.1.4","1.1.5","1.1.6","1.1.7","1.1.8","1.1.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-f8m3-jpxr-hm5x/GHSA-f8m3-jpxr-hm5x.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}