blosc2.c in Blosc C-Blosc2 through 2.0.0.beta.5 has a heap-based buffer overflow when there is a lack of space to write compressed data.
References
Link | Resource |
---|---|
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=26442 | Mailing List Third Party Advisory |
https://github.com/Blosc/c-blosc2/commit/c4c6470e88210afc95262c8b9fcc27e30ca043ee | Patch Third Party Advisory |
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=26442 | Mailing List Third Party Advisory |
https://github.com/Blosc/c-blosc2/commit/c4c6470e88210afc95262c8b9fcc27e30ca043ee | Patch Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
25 Apr 2025, 16:52
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:c-blosc2_project:c-blosc2:2.0.0:beta4:*:*:*:*:*:* cpe:2.3:a:c-blosc2_project:c-blosc2:2.0.0:beta5:*:*:*:*:*:* cpe:2.3:a:c-blosc2_project:c-blosc2:2.0.0:beta1:*:*:*:*:*:* cpe:2.3:a:c-blosc2_project:c-blosc2:2.0.0:a3:*:*:*:*:*:* cpe:2.3:a:c-blosc2_project:c-blosc2:2.0.0:beta2:*:*:*:*:*:* cpe:2.3:a:c-blosc2_project:c-blosc2:2.0.0:a4:*:*:*:*:*:* cpe:2.3:a:c-blosc2_project:c-blosc2:2.0.0:a5:*:*:*:*:*:* cpe:2.3:a:c-blosc2_project:c-blosc2:2.0.0:beta3:*:*:*:*:*:* |
cpe:2.3:a:blosc:c-blosc2:2.0.0:beta4:*:*:*:*:*:* cpe:2.3:a:blosc:c-blosc2:2.0.0:beta2:*:*:*:*:*:* cpe:2.3:a:blosc:c-blosc2:2.0.0:alpha4:*:*:*:*:*:* cpe:2.3:a:blosc:c-blosc2:2.0.0:alpha3:*:*:*:*:*:* cpe:2.3:a:blosc:c-blosc2:2.0.0:beta3:*:*:*:*:*:* cpe:2.3:a:blosc:c-blosc2:2.0.0:beta1:*:*:*:*:*:* cpe:2.3:a:blosc:c-blosc2:2.0.0:beta5:*:*:*:*:*:* cpe:2.3:a:blosc:c-blosc2:2.0.0:alpha5:*:*:*:*:*:* cpe:2.3:a:blosc:c-blosc2:2.0.0:alpha2:*:*:*:*:*:* |
First Time |
Blosc c-blosc2
Blosc |
21 Nov 2024, 05:23
Type | Values Removed | Values Added |
---|---|---|
References | () https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=26442 - Mailing List, Third Party Advisory | |
References | () https://github.com/Blosc/c-blosc2/commit/c4c6470e88210afc95262c8b9fcc27e30ca043ee - Patch, Third Party Advisory |
Information
Published : 2020-11-27 20:15
Updated : 2025-04-25 16:52
NVD link : CVE-2020-29367
Mitre link : CVE-2020-29367
CVE.ORG link : CVE-2020-29367
JSON object : View
Products Affected
blosc
- c-blosc2
CWE
CWE-787
Out-of-bounds Write