LWN.net Logo

bzip2: denial of service

Package(s):bzip2 CVE #(s):CVE-2008-1372
Created:March 24, 2008 Updated:May 9, 2008
Description:

From the CVE entry:

bzlib.c in bzip2 before 1.0.5 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted file that triggers a buffer over-read, as demonstrated by the PROTOS GENOME test suite.

Alerts:
Mandriva MDVSA-2008:075 2007-03-23
rPath rPSA-2008-0118-1 2008-03-21
Ubuntu USN-590-1 2008-03-24
Gentoo 200804-02 2008-04-02
Slackware SSA:2008-098-02 2008-04-08
Fedora FEDORA-2008-3037 2008-04-08
Fedora FEDORA-2008-2970 2008-04-08
SuSE SUSE-SR:2008:011 2008-05-09

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds
Powered by Rackspace Managed Hosting.