Описание
blosc2 heap-based buffer overflow
blosc2.c in Blosc C-Blosc2 through 2.0.0.beta.5 has a heap-based buffer overflow when there is a lack of space to write compressed data.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2020-29367
- https://github.com/Blosc/c-blosc2/commit/c4c6470e88210afc95262c8b9fcc27e30ca043ee
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=26442
- https://github.com/Blosc/python-blosc2/releases/tag/v0.1.7
- https://github.com/pypa/advisory-database/tree/main/vulns/blosc2/PYSEC-2020-343.yaml
Пакеты
Наименование
blosc2
pip
Затронутые версииВерсия исправления
< 0.1.7
0.1.7
Связанные уязвимости
CVSS3: 7.4
redhat
около 5 лет назад
blosc2.c in Blosc C-Blosc2 through 2.0.0.beta.5 has a heap-based buffer overflow when there is a lack of space to write compressed data.
CVSS3: 7.8
nvd
около 5 лет назад
blosc2.c in Blosc C-Blosc2 through 2.0.0.beta.5 has a heap-based buffer overflow when there is a lack of space to write compressed data.