CVE-2020-17361

Source
https://cve.org/CVERecord?id=CVE-2020-17361
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-17361.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-17361
Published
2020-08-12T18:15:17.403Z
Modified
2026-04-10T04:23:48.777919Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

An issue was discovered in ReadyTalk Avian 1.2.0. The vm::arrayCopy method defined in classpath-common.h returns silently when a negative length is provided (instead of throwing an exception). This could result in data being lost during the copy, with varying consequences depending on the subsequent use of the destination buffer. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

References

Affected packages

Git / github.com/readytalk/avian

Affected ranges

Type
GIT
Repo
https://github.com/readytalk/avian
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.2.0"
        }
    ]
}

Affected versions

v0.*
v0.0
v0.0.1
v0.3
v0.5
v0.6
v0.7
v0.7.1
v1.*
v1.0
v1.0.1
v1.1
v1.2.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-17361.json"