MGASA-2020-0385

Source
https://advisories.mageia.org/MGASA-2020-0385.html
Import Source
https://advisories.mageia.org/MGASA-2020-0385.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2020-0385
Related
Published
2020-10-16T15:44:59Z
Modified
2020-10-16T15:08:20Z
Summary
Updated brotli packages fix security vulnerability
Details

A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB (CVE-2020-8927).

References
Credits

Affected packages

Mageia:7 / brotli

Package

Name
brotli
Purl
pkg:rpm/mageia/brotli?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.7-2.1.mga7

Ecosystem specific

{
    "section": "core"
}