OSV-2024-221

Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/libspdm/OSV-2024-221.yaml
Published
2024-03-31T00:05:20.376065Z
Modified
2024-04-06T14:38:17.060185Z
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=67585

Crash type: Heap-buffer-overflow READ 1
Crash state:
libspdm_copy_mem
libspdm_get_response_chunk_send
libspdm_get_response_chunk_send
References

Affected packages

OSS-Fuzz / libspdm

Package

Name
libspdm

Affected ranges

Type
GIT
Repo
https://github.com/DMTF/libspdm.git
Events

Ecosystem specific

{
    "severity": "MEDIUM"
}

Database specific

{
    "introduced_range": "2586f39ce83d1e96747bdeebfb62eab020bcc1b1:d83ef43d3be34419e118fc3507fefdd0d0d2692c",
    "fixed_range": "d6a800391260d31f973a12e59fa9575066aee6d3:4c92ff5ced7862e4f2eea945dd723d2e1b1fc476"
}