Mageia 2020-0385: brotli security update
Summary
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an
attacker controlling the input length of a "one-shot" decompression request to
a script can trigger a crash, which happens when copying over chunks of data
larger than 2 GiB (CVE-2020-8927).
References
- https://bugs.mageia.org/show_bug.cgi?id=27406
- https://ubuntu.com/security/notices/USN-4568-1
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8927
Resolution
MGASA-2020-0385 - Updated brotli packages fix security vulnerability
SRPMS
- 7/core/brotli-1.0.7-2.1.mga7