bzlib.c in bzip2 before 1.0.5 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted file that triggers a buffer over-read, as demonstrated by the PROTOS GENOME test suite for Archive Formats.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Bzip2 | — | Upgrade macOS to the latest versionApply OS X security update 2009-003 | Dec 16, 2011 | Mar 18, 2008 |
| Centos_linux | — | Upgrade bzip2-libsUpgrade bzip2-develUpgrade bzip2 | Dec 1, 2016 | Mar 18, 2008 |
| Debian | — | Upgrade bzip2 | Jul 30, 2024 | Mar 18, 2008 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Mar 29, 2013 |
| Freebsd | — | Upgrade bzip2 | Dec 10, 2025 | Mar 20, 2008 |
| Gentoo Linux | — | Upgrade app-arch/bzip2.Upgrade app-admin/analog. | Oct 30, 2017 | Mar 18, 2008 |
| Oracle_linux | — | Upgrade bzip2-develUpgrade bzip2-libsUpgrade bzip2 | Oct 16, 2024 | Mar 18, 2008 |
| Suse | — | Upgrade libbz2-develUpgrade libbz2-1Upgrade libbz2-1-x86-64-v3Upgrade libbz2-1-32bitUpgrade bzip2Upgrade libbz2-1-x86Upgrade bzip2-doc | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libbz2-1.0 | Nov 8, 2024 | Mar 18, 2008 |
| Vmsa 2008 0019 | — | Apply ESX350-200811406-SG. | Nov 19, 2010 | Mar 18, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub