PT-2020-20053 · Buffer List+2 · Bl+2

Chalker

·

Published

2020-08-30

·

Updated

2022-11-14

·

CVE-2020-8244

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions bl versions prior to 4.0.3 bl versions prior to 3.0.1 bl versions prior to 2.2.1 bl versions prior to 1.2.3
Description A buffer over-read issue exists that could allow an attacker to supply user input that corrupts the BufferList state, potentially exposing uninitialized memory via regular slice() calls. This occurs when the consume() argument becomes negative.
Recommendations For versions prior to 4.0.3, update to version 4.0.3 or later to resolve the issue. For versions prior to 3.0.1, update to version 3.0.1 or later to resolve the issue. For versions prior to 2.2.1, update to version 2.2.1 or later to resolve the issue. For versions prior to 1.2.3, update to version 1.2.3 or later to resolve the issue.

Exploit

Fix

Buffer Over-read

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2408
ALT-PU-2022-3069
CVE-2020-8244
DLA-2698-1
GHSA-PP7H-53GX-MX7R
USN-5098-1
USN-5159-1

Affected Products

Alt Linux
Ubuntu
Bl