{"id":"GHSA-97xg-phpr-rg8q","summary":"Apache Commons BCEL vulnerable to out-of-bounds write","details":"Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode. This could be abused in applications that pass attacker-controllable data to those APIs, giving the attacker more control over the resulting bytecode than otherwise expected. Update to Apache Commons BCEL 6.6.0.","aliases":["CVE-2022-42920"],"modified":"2024-02-16T08:05:16.735617Z","published":"2022-11-07T19:00:22Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-11-07T21:05:28Z","nvd_published_at":"2022-11-07T13:15:00Z","cwe_ids":["CWE-787"],"severity":"CRITICAL"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-42920"},{"type":"WEB","url":"https://github.com/apache/commons-bcel/pull/147"},{"type":"PACKAGE","url":"https://github.com/apache/commons-bcel"},{"type":"WEB","url":"https://issues.apache.org/jira/browse/BCEL-363"},{"type":"WEB","url":"https://lists.apache.org/thread/lfxk7q8qmnh5bt9jm6nmjlv5hsxjhrz4"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LX3HEB4TV2BVCGDTK5BCLSYOZNQTOBN4"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QAMRHAKGIKZNHRBB4VLYTOIOIMMXCUCD"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QMVX6COVXZVS5GPWDODIRW6Z2GE7RPAQ"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LX3HEB4TV2BVCGDTK5BCLSYOZNQTOBN4"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QAMRHAKGIKZNHRBB4VLYTOIOIMMXCUCD"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QMVX6COVXZVS5GPWDODIRW6Z2GE7RPAQ"},{"type":"WEB","url":"https://security.gentoo.org/glsa/202401-25"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2022/11/07/2"}],"affected":[{"package":{"name":"org.apache.bcel:bcel","ecosystem":"Maven","purl":"pkg:maven/org.apache.bcel/bcel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.6.0"}]}],"versions":["5.2","6.0","6.1","6.2","6.3","6.3.1","6.4.0","6.4.1","6.5.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-97xg-phpr-rg8q/GHSA-97xg-phpr-rg8q.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}