{"id":"CVE-2020-28371","details":"An issue was discovered in ReadyTalk Avian 1.2.0 before 2020-10-27. The FileOutputStream.write() method in FileOutputStream.java has a boundary check to prevent out-of-bounds memory read/write operations. However, an integer overflow leads to bypassing this check and achieving the out-of-bounds access. NOTE: This vulnerability only affects products that are no longer supported by the maintainer","modified":"2026-07-08T19:03:16.295461Z","published":"2020-11-09T22:15:13.333Z","references":[{"type":"FIX","url":"https://github.com/ReadyTalk/avian/commit/0871979b298add320ca63f65060acb7532c8a0dd"},{"type":"FIX","url":"https://github.com/ReadyTalk/avian/pull/572"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/readytalk/avian","events":[{"introduced":"72c0547f4bdedc1ba8da2882317e3f758deab23f"},{"last_affected":"72c0547f4bdedc1ba8da2882317e3f758deab23f"},{"fixed":"0871979b298add320ca63f65060acb7532c8a0dd"}],"database_specific":{"cpe":"cpe:2.3:a:readytalk:avian:1.2.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.2.0"},{"last_affected":"1.2.0"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["1.2.0","v1.2.0"],"database_specific":{"vanir_signatures_modified":"2026-07-08T19:03:16Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["161694260855599367855421958645913010844","140373232215773158794410512667227169120","147285217384555310785516609865054958401","270785023055976051505704826886532062262"],"threshold":0.9},"id":"CVE-2020-28371-6a14a7f6","signature_type":"Line","signature_version":"v1","source":"https://github.com/readytalk/avian/commit/0871979b298add320ca63f65060acb7532c8a0dd","target":{"file":"classpath/java/io/FileOutputStream.java"}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/readytalk/avian/commit/0871979b298add320ca63f65060acb7532c8a0dd","target":{"file":"classpath/java/io/FileOutputStream.java","function":"write"},"deprecated":false,"digest":{"function_hash":"270870376968626371876760759397673686890","length":252},"id":"CVE-2020-28371-8520d70b"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-28371.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}