CVE-2014-9862 — Integer Overflow or Wraparound in Bsdiff
Severity
7.8HIGHNVD
EPSS
9.0%
top 7.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 22
Latest updateMay 13
Description
Integer signedness error in bspatch.c in bspatch in bsdiff, as used in Apple OS X before 10.11.6 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via a crafted patch file.
CVSS vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9
Affected Packages4 packages
🔴Vulnerability Details
2📋Vendor Advisories
4Debian▶
CVE-2014-9862: bsdiff - Integer signedness error in bspatch.c in bspatch in bsdiff, as used in Apple OS ...↗2014