CVE-2020-29367

blosc2.c in Blosc C-Blosc2 through 2.0.0.beta.5 has a heap-based buffer overflow when there is a lack of space to write compressed data.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 33%
VendorProductVersion
bloscc-blosc2
2.0.0:alpha2
bloscc-blosc2
2.0.0:alpha3
bloscc-blosc2
2.0.0:alpha4
bloscc-blosc2
2.0.0:alpha5
bloscc-blosc2
2.0.0:beta1
bloscc-blosc2
2.0.0:beta2
bloscc-blosc2
2.0.0:beta3
bloscc-blosc2
2.0.0:beta4
bloscc-blosc2
2.0.0:beta5
𝑥
= Vulnerable software versions