Integer signedness error in bspatch.c in bspatch in bsdiff, as used in Apple OS X before 10.11.6 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via a crafted patch file.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Bsdiff | — | Upgrade macOS to the latest version | Nov 11, 2016 | Jul 21, 2016 |
| Debian | — | Upgrade bsdiff | Mar 31, 2017 | Jul 21, 2016 |
| Freebsd | — | Upgrade FreeBSD | Dec 10, 2025 | Aug 11, 2016 |
| Gentoo Linux | — | Upgrade dev-util/bsdiff. | Mar 20, 2020 | Jul 22, 2016 |
| Suse | — | Upgrade bsdiff | Aug 26, 2016 | Jul 21, 2016 |
| Ubuntu | — | Upgrade bsdiff | Sep 16, 2020 | Jul 21, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub