A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB (CVE-2020-8927). . MGASA-2020-0385 - Updated brotli packages fix security vulnerability Publication date: 16 Oct 2020 URL: https://advisories.mageia.org/MGASA-2020-0385.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-8927 A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB (CVE-2020-8927). References: - https://bugs.mageia.org/show_bug.cgi?id=27406 - https://ubuntu.com/security/notices/USN-4568-1 - https://www.cve.org/CVERecord?id=CVE-2020-8927 SRPMS: - 7/core/brotli-1.0.7-2.1.mga7 . Mageia 2020-0386 security announcement revises Zlib packages to resolve a heap overflow vulnerability in versions 1.2.11 and prior. Brotli Security Update, Mageia Advisory, Buffer Overflow Fix, Software Vulnerability. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.