Description
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the "streaming" API as opposed to the "one-shot" API, and impose chunk size limits.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2476-1 | brotli security update |
Debian DSA |
DSA-4801-1 | brotli security update |
EUVD |
EUVD-2020-0057 | A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a \"one-shot\" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the \"streaming\" API as opposed to the \"one-shot\" API, and impose chunk size limits. |
Github GHSA |
GHSA-5v8v-66v8-mwm7 | Integer overflow in the bundled Brotli C library |
Ubuntu USN |
USN-4568-1 | Brotli vulnerability |
References
History
No history.
Subscriptions
Canonical
Subscribe
Ubuntu Linux
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Fedoraproject
Subscribe
Fedora
Subscribe
Google
Subscribe
Brotli
Subscribe
Microsoft
Subscribe
.net
Subscribe
.net Core
Subscribe
Powershell
Subscribe
Visual Studio 2019
Subscribe
Visual Studio 2022
Subscribe
Opensuse
Subscribe
Leap
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Rhel Dotnet
Subscribe
Status: PUBLISHED
Assigner: Google
Published:
Updated: 2024-08-04T10:12:11.066Z
Reserved: 2020-02-12T00:00:00.000Z
Link: CVE-2020-8927
No data.
Status : Modified
Published: 2020-09-15T10:15:12.887
Modified: 2024-11-21T05:39:41.370
Link: CVE-2020-8927
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Github GHSA
Ubuntu USN