LWN.net Logo

bzip2: denial of service

Package(s):bzip2 CVE #(s):CVE-2008-1372
Created:March 24, 2008 Updated:March 30, 2009
Description:

From the CVE entry:

bzlib.c in bzip2 before 1.0.5 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted file that triggers a buffer over-read, as demonstrated by the PROTOS GENOME test suite.

Alerts:
Gentoo 200903-40 2009-03-29
CentOS CESA-2008:0893 2008-09-16
Red Hat RHSA-2008:0893-01 2008-09-16
SuSE SUSE-SR:2008:011 2008-05-09
Fedora FEDORA-2008-2970 2008-04-08
Fedora FEDORA-2008-3037 2008-04-08
Slackware SSA:2008-098-02 2008-04-08
Gentoo 200804-02 2008-04-02
Ubuntu USN-590-1 2008-03-24
rPath rPSA-2008-0118-1 2008-03-21
Mandriva MDVSA-2008:075 2007-03-23

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds