icon

We found results for “

CVE-2020-36846

Good to know:

icon

Date: May 29, 2025

A buffer overflow, as described in CVE-2020-8927, exists in the embedded Brotli library.  Versions of IO::Compress::Brotli prior to 0.007 included a version of the brotli library prior to version 1.0.8, where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your IO::Compress::Brotli module to 0.007 or later. If one cannot update, we recommend to use the "streaming" API as opposed to the "one-shot" API, and impose chunk size limits.

Severity Score

Related Resources (37)

Severity Score

Weakness Type (CWE)

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

CWE-120

Dependency on Vulnerable Third-Party Component

CWE-1395

Top Fix

icon

Upgrade Version

Upgrade to version microsoft.netcore.app.runtime.linux-arm - 3.1.23;microsoft.netcore.app.runtime.linux-arm - 5.0.15;microsoft.netcore.app.runtime.linux-arm - 6.0.3;microsoft.netcore.app.runtime.linux-arm64 - 3.1.23;microsoft.netcore.app.runtime.linux-arm64 - 5.0.15;microsoft.netcore.app.runtime.linux-arm64 - 6.0.3;microsoft.netcore.app.runtime.linux-musl-arm64 - 3.1.23;microsoft.netcore.app.runtime.linux-musl-arm64 - 5.0.15;microsoft.netcore.app.runtime.linux-musl-arm64 - 6.0.3;microsoft.netcore.app.runtime.linux-x64 - 3.1.23;microsoft.netcore.app.runtime.linux-x64 - 5.0.15;microsoft.netcore.app.runtime.linux-x64 - 6.0.3;microsoft.netcore.app.runtime.osx-x64 - 3.1.23;microsoft.netcore.app.runtime.osx-x64 - 5.0.15;microsoft.netcore.app.runtime.osx-x64 - 6.0.3;microsoft.netcore.app.runtime.win-arm - 3.1.23;microsoft.netcore.app.runtime.win-arm - 5.0.15;microsoft.netcore.app.runtime.win-arm - 6.0.3;microsoft.netcore.app.runtime.win-arm64 - 3.1.23;microsoft.netcore.app.runtime.win-arm64 - 5.0.15;microsoft.netcore.app.runtime.win-arm64 - 6.0.3;microsoft.netcore.app.runtime.win-x64 - 3.1.23;microsoft.netcore.app.runtime.win-x64 - 5.0.15;microsoft.netcore.app.runtime.win-x64 - 6.0.3;microsoft.netcore.app.runtime.win-x86 - 3.1.23;microsoft.netcore.app.runtime.win-x86 - 5.0.15;microsoft.netcore.app.runtime.win-x86 - 6.0.3;microsoft.netcore.app.runtime.mono.llvm.aot.linux-arm64 - 5.0.15;microsoft.netcore.app.runtime.mono.llvm.aot.linux-arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.llvm.aot.linux-x64 - 5.0.15;microsoft.netcore.app.runtime.mono.llvm.aot.linux-x64 - 6.0.3;microsoft.netcore.app.runtime.mono.llvm.aot.osx-x64 - 5.0.15;microsoft.netcore.app.runtime.mono.llvm.aot.osx-x64 - 6.0.3;microsoft.netcore.app.runtime.mono.llvm.linux-arm64 - 5.0.15;microsoft.netcore.app.runtime.mono.llvm.linux-arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.llvm.linux-x64 - 5.0.15;microsoft.netcore.app.runtime.mono.llvm.linux-x64 - 6.0.3;microsoft.netcore.app.runtime.mono.llvm.osx-x64 - 5.0.15;microsoft.netcore.app.runtime.mono.llvm.osx-x64 - 6.0.3;microsoft.netcore.app.runtime.mono.linux-arm - 5.0.15;microsoft.netcore.app.runtime.mono.linux-arm - 6.0.3;microsoft.netcore.app.runtime.mono.linux-arm64 - 5.0.15;microsoft.netcore.app.runtime.mono.linux-arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.linux-musl-x64 - 5.0.15;microsoft.netcore.app.runtime.mono.linux-musl-x64 - 6.0.3;microsoft.netcore.app.runtime.mono.linux-x64 - 5.0.15;microsoft.netcore.app.runtime.mono.linux-x64 - 6.0.3;microsoft.netcore.app.runtime.mono.osx-x64 - 5.0.15;microsoft.netcore.app.runtime.mono.osx-x64 - 6.0.3;microsoft.netcore.app.runtime.browser-wasm - 5.0.15;microsoft.netcore.app.runtime.linux-musl-arm - 5.0.15;microsoft.netcore.app.runtime.linux-musl-arm - 6.0.3;microsoft.netcore.app.runtime.linux-musl-x64 - 5.0.15;microsoft.netcore.app.runtime.linux-musl-x64 - 6.0.3;microsoft.netcore.app.runtime.aot.linux-x64.cross.android-arm - 6.0.3;microsoft.netcore.app.runtime.aot.linux-x64.cross.android-arm64 - 6.0.3;microsoft.netcore.app.runtime.aot.linux-x64.cross.android-x64 - 6.0.3;microsoft.netcore.app.runtime.aot.linux-x64.cross.android-x86 - 6.0.3;microsoft.netcore.app.runtime.aot.linux-x64.cross.browser-wasm - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.android-arm - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.android-arm64 - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.android-x64 - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.android-x86 - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.browser-wasm - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.ios-arm - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.ios-arm64 - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.iossimulator-arm64 - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.iossimulator-x64 - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.iossimulator-x86 - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.maccatalyst-arm64 - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.maccatalyst-x64 - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.tvos-arm64 - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.tvossimulator-arm64 - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.tvossimulator-x64 - 6.0.3;microsoft.netcore.app.runtime.aot.win-x64.cross.android-arm - 6.0.3;microsoft.netcore.app.runtime.aot.win-x64.cross.android-arm.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.aot.win-x64.cross.android-arm64 - 6.0.3;microsoft.netcore.app.runtime.aot.win-x64.cross.android-arm64.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.aot.win-x64.cross.android-x64 - 6.0.3;microsoft.netcore.app.runtime.aot.win-x64.cross.android-x64.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.aot.win-x64.cross.android-x86 - 6.0.3;microsoft.netcore.app.runtime.aot.win-x64.cross.android-x86.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.aot.win-x64.cross.browser-wasm - 6.0.3;microsoft.netcore.app.runtime.aot.win-x64.cross.browser-wasm.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.android-arm - 6.0.3;microsoft.netcore.app.runtime.mono.android-arm.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.android-arm.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.android-arm.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.android-arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.android-arm64.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.android-arm64.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.android-arm64.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.android-x64 - 6.0.3;microsoft.netcore.app.runtime.mono.android-x64.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.android-x64.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.android-x64.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.android-x86 - 6.0.3;microsoft.netcore.app.runtime.mono.android-x86.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.android-x86.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.android-x86.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.browser-wasm - 6.0.3;microsoft.netcore.app.runtime.mono.browser-wasm.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.browser-wasm.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.browser-wasm.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.ios-arm - 6.0.3;microsoft.netcore.app.runtime.mono.ios-arm.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.ios-arm.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.ios-arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.ios-arm64.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.ios-arm64.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.ios-arm64.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.iossimulator-arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.iossimulator-arm64.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.iossimulator-arm64.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.iossimulator-arm64.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.iossimulator-x64 - 6.0.3;microsoft.netcore.app.runtime.mono.iossimulator-x64.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.iossimulator-x64.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.iossimulator-x64.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.iossimulator-x86 - 6.0.3;microsoft.netcore.app.runtime.mono.iossimulator-x86.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.iossimulator-x86.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.iossimulator-x86.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.maccatalyst-arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.maccatalyst-arm64.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.maccatalyst-arm64.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.maccatalyst-arm64.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.maccatalyst-x64 - 6.0.3;microsoft.netcore.app.runtime.mono.maccatalyst-x64.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.maccatalyst-x64.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.maccatalyst-x64.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.osx-arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.tvos-arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.tvos-arm64.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.tvos-arm64.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.tvos-arm64.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.tvossimulator-arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.tvossimulator-arm64.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.tvossimulator-arm64.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.tvossimulator-arm64.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.tvossimulator-x64 - 6.0.3;microsoft.netcore.app.runtime.mono.tvossimulator-x64.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.tvossimulator-x64.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.tvossimulator-x64.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.win-x64 - 6.0.3;microsoft.netcore.app.runtime.mono.win-x86 - 6.0.3;microsoft.netcore.app.runtime.osx-arm64 - 6.0.3;brotli - 1.0.8

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): HIGH
Integrity (I): HIGH
Availability (A): HIGH

Do you need more information?

Contact Us