Daemonology Bsdiff vulnerabilities
2 known vulnerabilities affecting daemonology/bsdiff.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1
Vulnerabilities
Page 1 of 1
CVE-2020-14315CRITICALCVSS 9.8v4.3vbsdiff 4.32020-09-16
CVE-2020-14315 [CRITICAL] CWE-787 CVE-2020-14315: A memory corruption vulnerability is present in bspatch as shipped in Colin Percival’s bsdiff tools
A memory corruption vulnerability is present in bspatch as shipped in Colin Percival’s bsdiff tools version 4.3. Insufficient checks when handling external inputs allows an attacker to bypass the sanity checks in place and write out of a dynamically allocated buffer boundaries.
nvdosv
CVE-2014-9862HIGHCVSS 7.8≥ 0, < 4.3-172016-07-22
CVE-2014-9862 [HIGH] CVE-2014-9862: Integer signedness error in bspatch
Integer signedness error in bspatch.c in bspatch in bsdiff, as used in Apple OS X before 10.11.6 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via a crafted patch file.
osv