Buffer overflow in brotli - CVE-2020-8927

 

Buffer overflow in brotli - CVE-2020-8927

Published: September 15, 2020 / Updated: September 22, 2020


Vulnerability identifier: #VU46905
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-8927
CWE-ID: CWE-120
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the "streaming" API as opposed to the "one-shot" API, and impose chunk size limits.


Affected software

brotli
Arch Linux
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
Fedora
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Public Cloud Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Basesystem
Server Applications Module
Python 3 Module
Opensuse
openSUSE Leap
Ubuntu
openEuler
Red Hat OpenShift Serverless
Windows Container Support for Red Hat OpenShift
OpenShift Virtualization
brotli (Debian package)
brotli (Alpine package)
rh-dotnet31-dotnet (Red Hat package)
samba (Alpine package)
rh-dotnet50-dotnet (Red Hat package)
dotnet5.0 (Red Hat package)
python-brotlipy-debuginfo
python-brotlipy-debugsource
python-brotlipy
python3-brotlipy-debuginfo
python3-brotlipy
golang-github-andybalholm-brotli
libbrotli1 (Ubuntu package)
brotli (Ubuntu package)
python3-brotli (Ubuntu package)
python-brotli (Ubuntu package)
brotli (Red Hat package)
libbrotlicommon1-debuginfo
libbrotlicommon1
libbrotlidec1-debuginfo
brotli-debuginfo
libbrotlidec1
brotli-debugsource
libbrotli-devel
libbrotlienc1-debuginfo
libbrotlienc1
python3-brotli
python2-brotli
brotli-help
brotli-devel
brotli
python-Brotli-debuginfo
python3-Brotli-debuginfo
python3-Brotli
python-Brotli-debugsource
dotnet-runtime-3.1
dotnet-targeting-pack-3.1
dotnet-hostfxr-3.1
dotnet-apphost-pack-3.1
aspnetcore-targeting-pack-3.1
aspnetcore-runtime-3.1
dotnet3.1 (Red Hat package)
dotnet3.1
dotnet-templates-3.1
dotnet-sdk-3.1-source-built-artifacts
dotnet-sdk-3.1
dotnet-targeting-pack-5.0
dotnet-runtime-5.0
dotnet-hostfxr-5.0
dotnet-apphost-pack-5.0
aspnetcore-targeting-pack-5.0
aspnetcore-runtime-5.0
dotnet-templates-5.0
dotnet-sdk-5.0
Service Telemetry Framework
IBM Robotic Process Automation
Cloud Pak for Security (CP4S)
Red Hat OpenShift Jaeger
Microsoft .NET Core
RoboHelp
Visual Studio
IBM Security Verify Access
Web Terminal

How to mitigate CVE-2020-8927

Install update from vendor's website.

brotli - update to 1.0.8
Red Hat OpenShift Serverless - update to 1.16.0
brotli (Debian package) - update to 1.0.7-2+deb10u1
Cloud Pak for Security (CP4S) - update to 1.8.0.0
Red Hat OpenShift Jaeger - addressed in versions 1.17.9, 1.20.4
Windows Container Support for Red Hat OpenShift - update to 2.0.1
rh-dotnet31-dotnet (Red Hat package) - update to 3.1.417-1.el7_9
samba (Alpine package) - update to 4.12.7-r0
rh-dotnet50-dotnet (Red Hat package) - update to 5.0.212-1.el7_9
dotnet5.0 (Red Hat package) - update to 5.0.212-1.el8_5
IBM Robotic Process Automation - update to 21.0.2.3
python-brotlipy-debuginfo - addressed in versions 0.6.0-2.6.1, 0.7.0-150100.3.6.1, 0.7.0-150300.3.3.1
python-brotlipy-debugsource - addressed in versions 0.6.0-2.6.1, 0.7.0-150100.3.6.1, 0.7.0-150300.3.3.1
python-brotlipy - update to 0.6.0-2.6.1
python3-brotlipy-debuginfo - addressed in versions 0.6.0-2.6.1, 0.7.0-150100.3.6.1, 0.7.0-150300.3.3.1
python3-brotlipy - addressed in versions 0.6.0-2.6.1, 0.7.0-150100.3.6.1, 0.7.0-150300.3.3.1
golang-github-andybalholm-brotli - addressed in versions 1.0.1-1.fc31, 1.0.1-1.fc32, 1.0.1-1.fc33
libbrotli1 (Ubuntu package) - addressed in versions 1.0.3-1ubuntu1.3, 1.0.3-1ubuntu1~16.04.2, 1.0.7-6ubuntu0.1
brotli (Ubuntu package) - addressed in versions 1.0.3-1ubuntu1.3, 1.0.3-1ubuntu1~16.04.2, 1.0.7-6ubuntu0.1
python3-brotli (Ubuntu package) - addressed in versions 1.0.3-1ubuntu1.3, 1.0.3-1ubuntu1~16.04.2, 1.0.7-6ubuntu0.1
python-brotli (Ubuntu package) - addressed in versions 1.0.3-1ubuntu1.3, 1.0.3-1ubuntu1~16.04.2
brotli (Red Hat package) - update to 1.0.6-3.el8
libbrotlicommon1-debuginfo - update to 1.0.7-3.3.1
libbrotlicommon1 - update to 1.0.7-3.3.1
libbrotlidec1-debuginfo - update to 1.0.7-3.3.1
brotli-debuginfo - update to 1.0.7-3.3.1
libbrotlidec1 - update to 1.0.7-3.3.1
brotli-debugsource - update to 1.0.7-3.3.1
libbrotli-devel - update to 1.0.7-3.3.1
libbrotlienc1-debuginfo - update to 1.0.7-3.3.1
libbrotlienc1 - update to 1.0.7-3.3.1
brotli-debuginfo - update to 1.0.7-4
brotli-debugsource - update to 1.0.7-4
python3-brotli - update to 1.0.7-4
python2-brotli - update to 1.0.7-4
brotli-help - update to 1.0.7-4
brotli-devel - update to 1.0.7-4
brotli - update to 1.0.7-4
python-Brotli-debuginfo - update to 1.0.7-150200.3.3.1
python3-Brotli-debuginfo - update to 1.0.7-150200.3.3.1
python3-Brotli - update to 1.0.7-150200.3.3.1
python-Brotli-debugsource - update to 1.0.7-150200.3.3.1
brotli - addressed in versions 1.0.9-3.fc31, 1.0.9-3.fc32, 1.0.9-3.fc33, 1.0.9-10.el7
Web Terminal - update to 1.3
OpenShift Virtualization - addressed in versions 2.6.6, 4.8.0
dotnet-runtime-3.1 - update to 3.1.23-1.0.1
dotnet-targeting-pack-3.1 - update to 3.1.23-1.0.1
dotnet-hostfxr-3.1 - update to 3.1.23-1.0.1
dotnet-apphost-pack-3.1 - update to 3.1.23-1.0.1
aspnetcore-targeting-pack-3.1 - update to 3.1.23-1.0.1
aspnetcore-runtime-3.1 - update to 3.1.23-1.0.1
dotnet3.1 (Red Hat package) - update to 3.1.417-1.el8_5
dotnet3.1 - addressed in versions 3.1.417-1.fc34, 3.1.417-1.fc35, 3.1.417-1.fc36
dotnet-templates-3.1 - update to 3.1.417-1.0.1
dotnet-sdk-3.1-source-built-artifacts - update to 3.1.417-1.0.1
dotnet-sdk-3.1 - update to 3.1.417-1.0.1
dotnet-targeting-pack-5.0 - update to 5.0.15-1.0.1
dotnet-runtime-5.0 - update to 5.0.15-1.0.1
dotnet-hostfxr-5.0 - update to 5.0.15-1.0.1
dotnet-apphost-pack-5.0 - update to 5.0.15-1.0.1
aspnetcore-targeting-pack-5.0 - update to 5.0.15-1.0.1
aspnetcore-runtime-5.0 - update to 5.0.15-1.0.1
dotnet-templates-5.0 - update to 5.0.212-1.0.1
dotnet-sdk-5.0 - update to 5.0.212-1.0.1

External References

Related Security Bulletins