{"id":"OSV-2024-221","summary":"Heap-buffer-overflow in libspdm_copy_mem","details":"OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=67585\n\n```\nCrash type: Heap-buffer-overflow READ 1\nCrash state:\nlibspdm_copy_mem\nlibspdm_get_response_chunk_send\nlibspdm_get_response_chunk_send\n```\n","modified":"2024-04-06T14:38:17.060185Z","published":"2024-03-31T00:05:20.376065Z","references":[{"type":"REPORT","url":"https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=67585"}],"affected":[{"package":{"name":"libspdm","ecosystem":"OSS-Fuzz","purl":"pkg:generic/libspdm"},"ranges":[{"type":"GIT","repo":"https://github.com/DMTF/libspdm.git","events":[{"introduced":"c2d004512067a23f483a99224165accf3d9d89f2"},{"fixed":"4c92ff5ced7862e4f2eea945dd723d2e1b1fc476"}]}],"ecosystem_specific":{"severity":"MEDIUM"},"database_specific":{"source":"https://github.com/google/oss-fuzz-vulns/blob/main/vulns/libspdm/OSV-2024-221.yaml","introduced_range":"2586f39ce83d1e96747bdeebfb62eab020bcc1b1:d83ef43d3be34419e118fc3507fefdd0d0d2692c","fixed_range":"d6a800391260d31f973a12e59fa9575066aee6d3:4c92ff5ced7862e4f2eea945dd723d2e1b1fc476"}}],"schema_version":"1.7.3"}