Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 before 1.0.6 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted compressed file.
2010-09-28T18:00:02.340
2025-04-11T00:51:21.963
Deferred
CVSSv2: 5.1 (MEDIUM)
AV:N/AC:H/Au:N/C:P/I:P/A:P
4.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | bzip | bzip2 | ≤ 1.0.5 | Yes |
Application | bzip | bzip2 | 0.9 | Yes |
Application | bzip | bzip2 | 0.9.0 | Yes |
Application | bzip | bzip2 | 0.9.0a | Yes |
Application | bzip | bzip2 | 0.9.0b | Yes |
Application | bzip | bzip2 | 0.9.0c | Yes |
Application | bzip | bzip2 | 0.9.5_a | Yes |
Application | bzip | bzip2 | 0.9.5_b | Yes |
Application | bzip | bzip2 | 0.9.5_c | Yes |
Application | bzip | bzip2 | 0.9.5_d | Yes |
Application | bzip | bzip2 | 0.9.5a | Yes |
Application | bzip | bzip2 | 0.9.5b | Yes |
Application | bzip | bzip2 | 0.9.5c | Yes |
Application | bzip | bzip2 | 0.9.5d | Yes |
Application | bzip | bzip2 | 0.9_a | Yes |
Application | bzip | bzip2 | 0.9_b | Yes |
Application | bzip | bzip2 | 0.9_c | Yes |
Application | bzip | bzip2 | 1.0 | Yes |
Application | bzip | bzip2 | 1.0.1 | Yes |
Application | bzip | bzip2 | 1.0.2 | Yes |
Application | bzip | bzip2 | 1.0.3 | Yes |
Application | bzip | bzip2 | 1.0.4 | Yes |
Application | libzip2 | libzip2 | ≤ 1.0.5 | Yes |