5.1 MEDIUM
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): None (N)
- Vulnerable System Impact Integrity (VI): None (N)
- Vulnerable System Impact Availability (VA): Low (L)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): None (N)
- Modified Vulnerable System Impact Integrity (MVI): None (N)
- Modified Vulnerable System Impact Availability (MVA): Low (L)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
18 packages
- lbzip2
- pbzip2
- bzip2_1_1
- indexed-bzip2
- minimal-bootstrap.bzip2
- haskellPackages.bzip2-clib
- perlPackages.CompressBzip2
- perl5Packages.CompressBzip2
- perl538Packages.CompressBzip2
- perl540Packages.CompressBzip2
- perlPackages.CompressRawBzip2
- minimal-bootstrap.bzip2-static
- perl5Packages.CompressRawBzip2
- python312Packages.indexed-bzip2
- python313Packages.indexed-bzip2
- python314Packages.indexed-bzip2
- perl538Packages.CompressRawBzip2
- perl540Packages.CompressRawBzip2
- @LeSuisse restored package bzip2_1_1
- @LeSuisse accepted
- @LeSuisse published on GitHub
Off-by-One Leading to Out-of-Bounds Write in bzip2
bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service). This issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67
References
Affected products
- ==35d122a3df8b0cc4082a4d89fdc6ee99f375fe67
- =<1.0.8
Matching in nixpkgs
pkgs.bzip2
High-quality data compression program
pkgs.bzip2_1_1
High-quality data compression program
-
nixos-unstable 2020-08-11
- nixpkgs-unstable 2020-08-11
- nixos-unstable-small 2020-08-11
Ignored packages (17)
pkgs.lbzip2
Parallel bzip2 compression utility
pkgs.pbzip2
Parallel implementation of bzip2 for multi-core machines
pkgs.indexed-bzip2
Python library for parallel decompression and seeking within compressed bzip2 files
pkgs.minimal-bootstrap.bzip2
High-quality data compression program
pkgs.haskellPackages.bzip2-clib
bzip2 C sources
pkgs.perlPackages.CompressBzip2
Interface to Bzip2 compression library
-
nixos-unstable Bzip2-2.28
- nixpkgs-unstable Bzip2-2.28
- nixos-unstable-small Bzip2-2.28
pkgs.perl5Packages.CompressBzip2
Interface to Bzip2 compression library
-
nixos-unstable Bzip2-2.28
- nixpkgs-unstable Bzip2-2.28
- nixos-unstable-small Bzip2-2.28
pkgs.perl538Packages.CompressBzip2
None
pkgs.perl540Packages.CompressBzip2
None
pkgs.perlPackages.CompressRawBzip2
Low-Level Interface to bzip2 compression library
-
nixos-unstable Bzip2-2.206
- nixpkgs-unstable Bzip2-2.206
- nixos-unstable-small Bzip2-2.206
pkgs.minimal-bootstrap.bzip2-static
High-quality data compression program
pkgs.perl5Packages.CompressRawBzip2
Low-Level Interface to bzip2 compression library
-
nixos-unstable Bzip2-2.206
- nixpkgs-unstable Bzip2-2.206
- nixos-unstable-small Bzip2-2.206
pkgs.python312Packages.indexed-bzip2
None
pkgs.python313Packages.indexed-bzip2
Python library for parallel decompression and seeking within compressed bzip2 files
-
nixos-unstable indexed_bzip2-1.6.0
- nixpkgs-unstable indexed_bzip2-1.6.0
- nixos-unstable-small indexed_bzip2-1.6.0
pkgs.python314Packages.indexed-bzip2
Python library for parallel decompression and seeking within compressed bzip2 files
-
nixos-unstable indexed_bzip2-1.6.0
- nixpkgs-unstable indexed_bzip2-1.6.0
- nixos-unstable-small indexed_bzip2-1.6.0
pkgs.perl538Packages.CompressRawBzip2
None
pkgs.perl540Packages.CompressRawBzip2
None
Package maintainers
-
@Mic92 Jörg Thalheim <joerg@thalheim.io>