Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 before 1.0.6 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted compressed file.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Airport | — | Apply OS X security update 2011-004Upgrade macOS to the latest versionApply OS X security update 2011-001 | Aug 28, 2015 | Sep 28, 2010 |
| Apple Osx Bzip2 | — | Apply OS X security update 2011-001Upgrade macOS to the latest version | Dec 16, 2011 | Sep 28, 2010 |
| Apple Osx Clamav | — | Upgrade macOS to the latest versionApply OS X security update 2011-001 | Dec 16, 2011 | Sep 28, 2010 |
| Centos_linux | — | Upgrade bzip2-libsUpgrade bzip2Upgrade bzip2-devel | Dec 1, 2016 | Sep 28, 2010 |
| Debian | — | Upgrade bzip2Upgrade clamav | Jul 30, 2024 | Sep 28, 2010 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Nov 27, 2014 |
| Freebsd | — | Upgrade bzip2 | Dec 10, 2025 | Oct 25, 2010 |
| Gentoo Linux | — | Upgrade app-antivirus/clamav.Upgrade app-arch/bzip2. | Oct 30, 2017 | Sep 28, 2010 |
| Oracle_linux | — | Upgrade bzip2-develUpgrade bzip2-libsUpgrade bzip2 | Oct 16, 2024 | Sep 28, 2010 |
| Suse | — | Upgrade clamav-docs-htmlUpgrade libfreshclam4Upgrade libclamav12Upgrade libbz2-develUpgrade clamav-milterUpgrade libbz2-1-x86-64-v3Upgrade bzip2Upgrade clamavUpgrade bzip2-docUpgrade libbz2-1Upgrade libbz2-1-32bitUpgrade libclammspack0Upgrade clamav-develUpgrade libfreshclam3Upgrade libclamav7Upgrade libbz2-1-x86 | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libbz2-1.0Upgrade libclamav6Upgrade bzip2Upgrade dpkg | Nov 8, 2024 | Sep 28, 2010 |
| Vmsa 2010 0019 | — | Upgrade VMware ESX 4.0 to build number 360236Upgrade VMware ESX 4.1 to build number 381591Upgrade VMware ESX 3.5 to build number 317866 | Dec 7, 2010 | Sep 28, 2010 |
| Vmsa 2012 0005 | — | Upgrade VMware ESXi 5.0 to build number 515841 | Mar 23, 2012 | Sep 28, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub