CVE-2020-14150
published 2020-06-15CVE-2020-14150: GNU Bison before 3.5.4 allows attackers to cause a denial of service (application crash). NOTE: there is a risk only if Bison is used with untrusted input, and…
PriorityP415medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.39%
31.6th percentile
GNU Bison before 3.5.4 allows attackers to cause a denial of service (application crash). NOTE: there is a risk only if Bison is used with untrusted input, and an observed bug happens to cause unsafe behavior with a specific compiler/architecture. The bug reports were intended to show that a crash may occur in Bison itself, not that a crash may occur in code that is generated by Bison.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bison | < bison 2:3.6.1+dfsg-1 (bookworm) | bison 2:3.6.1+dfsg-1 (bookworm) |
| gnu | bison | < 3.5.4 | 3.5.4 |
| gnu | bison | >= 0 < 2:3.6.1+dfsg-1 | 2:3.6.1+dfsg-1 |
| gnu | bison | >= 0 < 2:3.6.1+dfsg-1 | 2:3.6.1+dfsg-1 |
| gnu | bison | >= 0 < 2:3.6.1+dfsg-1 | 2:3.6.1+dfsg-1 |
| gnu | bison | >= 0 < 2:3.6.1+dfsg-1 | 2:3.6.1+dfsg-1 |
| msrc | cm1_bison_3.1-4_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
GNU Bison before 3.5.4 allows attackers to cause a denial of service (application crash). NOTE: there is a risk only if Bison is used with untrusted input, and an observed bug happens to cause unsafe
vendor_msrc·2020-06-09·CVSS 5.5
CVE-2020-14150 [MEDIUM] GNU Bison before 3.5.4 allows attackers to cause a denial of service (application crash). NOTE: there is a risk only if Bison is used with untrusted input, and an observed bug happens to cause unsafe
GNU Bison before 3.5.4 allows attackers to cause a denial of service (application crash). NOTE: there is a risk only if Bison is used with untrusted input, and an observed bug happens to cause unsafe behavior with a specific compiler/architecture. The bug reports were intended to show that a crash may occur in Bison itself, not that a crash may occur in code that is generated by Bison.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to tran
Red Hat
bison: allows attackers to cause a denial of service
vendor_redhat·2020-04-05·CVSS 5.5
CVE-2020-14150 [MEDIUM] CWE-122 bison: allows attackers to cause a denial of service
bison: allows attackers to cause a denial of service
GNU Bison before 3.5.4 allows attackers to cause a denial of service (application crash). NOTE: there is a risk only if Bison is used with untrusted input, and an observed bug happens to cause unsafe behavior with a specific compiler/architecture. The bug reports were intended to show that a crash may occur in Bison itself, not that a crash may occur in code that is generated by Bison.
Mitigation: To mitigate this flaw, do not use Bison on untrusted input.
Package: bison (Red Hat Enterprise Linux 5) - Out of support scope
Package: bison (Red Hat Enterprise Linux 6) - Out of support scope
Package: bison (Red Hat Enterprise Linux 7) - Will not fix
Package: bison (Red Hat Enterprise Linux 8) - Will not fix
Debian
CVE-2020-14150: bison - GNU Bison before 3.5.4 allows attackers to cause a denial of service (applicatio...
vendor_debian·2020·CVSS 5.5
CVE-2020-14150 [MEDIUM] CVE-2020-14150: bison - GNU Bison before 3.5.4 allows attackers to cause a denial of service (applicatio...
GNU Bison before 3.5.4 allows attackers to cause a denial of service (application crash). NOTE: there is a risk only if Bison is used with untrusted input, and an observed bug happens to cause unsafe behavior with a specific compiler/architecture. The bug reports were intended to show that a crash may occur in Bison itself, not that a crash may occur in code that is generated by Bison.
Scope: local
bookworm: resolved (fixed in 2:3.6.1+dfsg-1)
bullseye: resolved (fixed in 2:3.6.1+dfsg-1)
forky: resolved (fixed in 2:3.6.1+dfsg-1)
sid: resolved (fixed in 2:3.6.1+dfsg-1)
trixie: resolved (fixed in 2:3.6.1+dfsg-1)
GHSA
GHSA-wqmg-pp5q-5hqr: GNU Bison before 3
ghsa_unreviewed·2022-05-24
CVE-2020-14150 [MEDIUM] GHSA-wqmg-pp5q-5hqr: GNU Bison before 3
GNU Bison before 3.5.4 allows attackers to cause a denial of service (application crash).
OSV
CVE-2020-14150: GNU Bison before 3
osv·2020-06-15·CVSS 5.5
CVE-2020-14150 [MEDIUM] CVE-2020-14150: GNU Bison before 3
GNU Bison before 3.5.4 allows attackers to cause a denial of service (application crash). NOTE: there is a risk only if Bison is used with untrusted input, and an observed bug happens to cause unsafe behavior with a specific compiler/architecture. The bug reports were intended to show that a crash may occur in Bison itself, not that a crash may occur in code that is generated by Bison.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-14150 bison: allows attackers to cause a denial of service [fedora-all]
bugzilla·2020-06-16·CVSS 5.5
CVE-2020-14150 [MEDIUM] CVE-2020-14150 bison: allows attackers to cause a denial of service [fedora-all]
CVE-2020-14150 bison: allows attackers to cause a denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versi
Bugzilla
CVE-2020-14150 bison: allows attackers to cause a denial of service
bugzilla·2020-06-16·CVSS 5.5
CVE-2020-14150 [MEDIUM] CVE-2020-14150 bison: allows attackers to cause a denial of service
CVE-2020-14150 bison: allows attackers to cause a denial of service
GNU Bison before 3.5.4 allows attackers to cause a denial of service (application crash).
Reference:
https://lists.gnu.org/archive/html/info-gnu/2020-04/msg00000.html
Discussion:
Created bison tracking bugs for this issue:
Affects: fedora-all [bug 1847609]
---
Mitigation:
To mitigate this flaw, do not use Bison on untrusted input.
---
The CVE seems to encapsulate several heap buffer overflows and assertion failures found listed as "[bison crash]" on [1]. Most of the issues stem from the same flawed code that is patched in [2]. All issues require untrusted input to be provided to bison, and likely will lead to bison crashing.
1. https://lists.gnu.org/archive/html/bug-bison/2020-03/index.html
2. https://github.com
2020-06-15
Published