{ "affected": [ { "ranges": [ { "database_specific": { "cpe": [ "cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*", "cpe:2.3:a:microsoft:.net_core:*:*:*:*:*:*:*:*" ], "extracted_events": [ { "introduced": "5.0" }, { "last_affected": "5.0.14" }, { "introduced": "3.1" }, { "last_affected": "3.1.22" } ], "source": "CPE_RANGE" }, "events": [ { "introduced": "62bcac3998e1168f4a34b775a06d6451b5ffca7b" }, { "last_affected": "c01985a0f4aa6036831dae2088fc33d9297a5f08" }, { "introduced": "5c0a0489d157ca82fca6f9b73c682f118e8c4a8a" }, { "last_affected": "5ab95474faeba1ca47e19a83c46b73d1a10b7f77" } ], "repo": "https://github.com/dotnet/core", "type": "GIT" } ] }, { "ranges": [ { "database_specific": { "cpe": "cpe:2.3:a:google:brotli:*:*:*:*:*:*:*:*", "extracted_events": [ { "introduced": "0" }, { "fixed": "1.0.8" } ], "source": [ "CPE_RANGE", "REFERENCES" ] }, "events": [ { "introduced": "0" }, { "fixed": "db361a0bb901d6a71c7cbf1370d97b3703482e3b" }, { "fixed": "e61745a6b7add50d380cfd7d3883dd6c62fc2c71" } ], "repo": "https://github.com/google/brotli", "type": "GIT" } ] }, { "ranges": [ { "database_specific": { "cpe": "cpe:2.3:a:microsoft:powershell:*:*:*:*:*:*:*:*", "extracted_events": [ { "introduced": "7.0" }, { "fixed": "7.0.9" }, { "introduced": "7.1" }, { "fixed": "7.1.6" }, { "introduced": "7.2" }, { "fixed": "7.2.2" } ], "source": "CPE_RANGE" }, "events": [ { "introduced": "b54b188c1804d4dcebb09a8be3a67916abd94fd7" }, { "fixed": "3269c95a72af9a3a161884dbae99eae0352b3e7d" }, { "introduced": "fa01333bfeef5dd7769143e2b4ec7ffdb70c62c8" }, { "fixed": "dc703cb4aa619e31f2f48f2b9bf613e9aa6cff76" }, { "introduced": "bec5c36d9da67bfcf5b88834f03b326c89f100c5" }, { "fixed": "2bbf08166ff49469988420af883407e1dd1ef4ed" } ], "repo": "https://github.com/powershell/powershell", "type": "GIT" } ] } ], "database_specific": { "unresolved_ranges": [ { "cpes": [ "cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:*" ], "extracted_events": [ { "introduced": "16.0" }, { "last_affected": "16.11" } ], "source": "CPE_RANGE", "vendor_product": "microsoft:visual_studio_2019" }, { "cpes": [ "cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*" ], "extracted_events": [ { "introduced": "17.0" }, { "last_affected": "17.0.7" } ], "source": "CPE_RANGE", "vendor_product": "microsoft:visual_studio_2022" }, { "cpes": [ "cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*", "cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*", "cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*" ], "extracted_events": [ { "introduced": "16.04" }, { "last_affected": "16.04" }, { "introduced": "18.04" }, { "last_affected": "18.04" }, { "introduced": "20.04" }, { "last_affected": "20.04" } ], "source": "CPE_STRING", "vendor_product": "canonical:ubuntu_linux" }, { "cpes": [ "cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*", "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*" ], "extracted_events": [ { "introduced": "9.0" }, { "last_affected": "9.0" }, { "introduced": "10.0" }, { "last_affected": "10.0" } ], "source": "CPE_STRING", "vendor_product": "debian:debian_linux" }, { "cpes": [ "cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*", "cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*", "cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*", "cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*", "cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*", "cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*" ], "extracted_events": [ { "introduced": "31" }, { "last_affected": "31" }, { "introduced": "32" }, { "last_affected": "32" }, { "introduced": "33" }, { "last_affected": "33" }, { "introduced": "34" }, { "last_affected": "34" }, { "introduced": "35" }, { "last_affected": "35" }, { "introduced": "36" }, { "last_affected": "36" } ], "source": "CPE_STRING", "vendor_product": "fedoraproject:fedora" }, { "cpes": [ "cpe:2.3:a:microsoft:visual_studio_2022:17.1:*:*:*:*:*:*:*" ], "extracted_events": [ { "introduced": "17.1" }, { "last_affected": "17.1" } ], "source": "CPE_STRING", "vendor_product": "microsoft:visual_studio_2022" }, { "cpes": [ "cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:*" ], "extracted_events": [ { "introduced": "15.2" }, { "last_affected": "15.2" } ], "source": "CPE_STRING", "vendor_product": "opensuse:leap" } ] }, "details": "A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a \"one-shot\" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the \"streaming\" API as opposed to the \"one-shot\" API, and impose chunk size limits.", "id": "CVE-2020-8927", "modified": "2026-07-08T05:35:53.902247734Z", "published": "2020-09-15T10:15:12.887Z", "references": [ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/356JOYTWW4BWSZ42SEFLV7NYHL3S3AEH/" }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4TOGTZ2ZWDH662ZNFFSZVL3M5AJXV6JF/" }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J4E265WKWKYMK2RYYSIXBEGZTDY5IQE6/" }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M4VCDOJGL6BK3HB4XRD2WETBPYX2ITF6/" }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MMBKACMLSRX7JJSKBTR35UOEP2WFR6QP/" }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MQLM7ABVCYJLF6JRPF3M3EBXW63GNC27/" }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W23CUADGMVMQQNFKHPHXVP7RPZJZNN6I/" }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WW62OZEY2GHJL4JCOLJRBSRETXDHMWRK/" }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZXEQ3GQVELA2T4HNZG7VPMS2HDVXMJRG/" }, { "type": "ADVISORY", "url": "http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00108.html" }, { "type": "ADVISORY", "url": "https://github.com/google/brotli/releases/tag/v1.0.9" }, { "type": "ADVISORY", "url": "https://lists.debian.org/debian-lts-announce/2020/12/msg00003.html" }, { "type": "ADVISORY", "url": "https://usn.ubuntu.com/4568-1/" }, { "type": "ADVISORY", "url": "https://www.debian.org/security/2020/dsa-4801" } ], "severity": [ { "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L", "type": "CVSS_V3" } ] }