{"id":"UBUNTU-CVE-2020-14315","details":"A memory corruption vulnerability is present in bspatch as shipped in Colin Percival’s bsdiff tools version 4.3. Insufficient checks when handling external inputs allows an attacker to bypass the sanity checks in place and write out of a dynamically allocated buffer boundaries.","modified":"2026-05-20T16:04:10.206794053Z","published":"2020-09-16T14:15:00Z","upstream":["CVE-2020-14315"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2020-14315"},{"type":"REPORT","url":"https://www.openwall.com/lists/oss-security/2020/07/09/2"},{"type":"REPORT","url":"https://www.freebsd.org/security/advisories/FreeBSD-SA-16:29.bspatch.asc"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2020-14315"}],"affected":[{"package":{"name":"bsdiff","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/bsdiff?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.3-15","4.3-15+deb8u1build0.16.04.1"],"ecosystem_specific":{"binaries":[{"binary_name":"bsdiff","binary_version":"4.3-15+deb8u1build0.16.04.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-14315.json"}},{"package":{"name":"bsdiff","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/bsdiff?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.3-19","4.3-20"],"ecosystem_specific":{"binaries":[{"binary_name":"bsdiff","binary_version":"4.3-20"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-14315.json"}},{"package":{"name":"bsdiff","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/bsdiff?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.3-21"],"ecosystem_specific":{"binaries":[{"binary_name":"bsdiff","binary_version":"4.3-21"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-14315.json"}},{"package":{"name":"bsdiff","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/bsdiff?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.3-22","4.3-23"],"ecosystem_specific":{"binaries":[{"binary_version":"4.3-23","binary_name":"bsdiff"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-14315.json"}},{"package":{"name":"bsdiff","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/bsdiff?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.3-23"],"ecosystem_specific":{"binaries":[{"binary_version":"4.3-23","binary_name":"bsdiff"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-14315.json"}},{"package":{"name":"bsdiff","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/bsdiff?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.3-23"],"ecosystem_specific":{"binaries":[{"binary_name":"bsdiff","binary_version":"4.3-23"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-14315.json"}},{"package":{"name":"bsdiff","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/bsdiff?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.3-23","4.3-23build1"],"ecosystem_specific":{"binaries":[{"binary_name":"bsdiff","binary_version":"4.3-23build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-14315.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}