CVE-2008-1372Improper Restriction of Operations within the Bounds of a Memory Buffer in Bzip2

Severity
4.3MEDIUMNVD
EPSS
7.7%
top 8.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 18
Latest updateMay 3

Description

bzlib.c in bzip2 before 1.0.5 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted file that triggers a buffer over-read, as demonstrated by the PROTOS GENOME test suite for Archive Formats.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

debiandebian/bzip2< bzip2 1.0.5-0.1 (bookworm)
Debianbzip/bzip2< 1.0.5-0.1+3
NVDbzip/bzip212 versions+11

🔴Vulnerability Details

2
GHSA
GHSA-prgg-m9pm-qvgm: bzlib2022-05-03
OSV
CVE-2008-1372: bzlib2008-03-18

📋Vendor Advisories

3
Ubuntu
bzip2 vulnerability2008-03-24
Red Hat
bzip2: crash on malformed archive file2008-03-18
Debian
CVE-2008-1372: bzip2 - bzlib.c in bzip2 before 1.0.5 allows user-assisted remote attackers to cause a d...2008

💬Community

1
Bugzilla
CVE-2008-1372 bzip2: crash on malformed archive file2008-03-19
CVE-2008-1372 — Debian Bzip2 vulnerability | cvebase