Nixpkgs security tracker

Login with GitHub

Suggestion detail

Dismissed
Permalink CVE-2024-3508
4.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
updated 6 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    9 packages
    • bzip2
    • lbzip2
    • pbzip2
    • bzip2_1_1
    • indexed-bzip2
    • haskellPackages.bzip2-clib
    • python312Packages.indexed-bzip2
    • python313Packages.indexed-bzip2
    • tests.pkg-config.defaultPkgConfigPackages.bzip2
  • @LeSuisse dismissed
Bzip2: compressed content bomb leads to denial of service of bombastic api

A flaw was found in Bombastic, which allows authenticated users to upload compressed (bzip2 or zstd) SBOMs. The API endpoint verifies the presence of some fields and values in the JSON. To perform this verification, the uploaded file must first be decompressed.

References

Affected products

bzip2
  • ==faa7a496c5d98e0f0859dd2c623eddf82289eaa8
SBOM-Management-(Bombastic)
Ignored packages (9)

pkgs.bzip2

High-quality data compression program

  • nixos-unstable -

pkgs.lbzip2

Parallel bzip2 compression utility

  • nixos-unstable -
    • nixpkgs-unstable 2.5

pkgs.pbzip2

Parallel implementation of bzip2 for multi-core machines

  • nixos-unstable -

pkgs.bzip2_1_1

High-quality data compression program

pkgs.indexed-bzip2

Python library for parallel decompression and seeking within compressed bzip2 files

  • nixos-unstable -