CVE-2023-29415
published 2023-04-06CVE-2023-29415: An issue was discovered in libbzip3.a in bzip3 before 1.3.0. A denial of service (process hang) can occur with a crafted archive because bzip3 does not follow…
PriorityP426medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
0.89%
55.9th percentile
An issue was discovered in libbzip3.a in bzip3 before 1.3.0. A denial of service (process hang) can occur with a crafted archive because bzip3 does not follow the required procedure for interacting with libsais.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bzip3_project | bzip3 | < 1.3.0 | 1.3.0 |
| bzip3_project | bzip3 | >= 0 < 1.2.2-2 | 1.2.2-2 |
| bzip3_project | bzip3 | >= 0 < 1.2.2-2 | 1.2.2-2 |
| bzip3_project | bzip3 | >= 0 < 1.2.2-2 | 1.2.2-2 |
| debian | bzip3 | < bzip3 1.2.2-2 (bookworm) | bzip3 1.2.2-2 (bookworm) |
| debian | debian_linux | — | — |
| fedorindutny | ip | 0 – 2.0.1 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
ghsa9.8CRITICAL
osv6.5MEDIUM
vendor_redhat9.8CRITICAL
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
node-ip: Incomplete fix for CVE-2023-42282
vendor_redhat·2024-02-20·CVSS 9.8
CVE-2024-29415 [CRITICAL] CWE-918 node-ip: Incomplete fix for CVE-2023-42282
node-ip: Incomplete fix for CVE-2023-42282
The ip package through 2.0.1 for Node.js might allow SSRF because some IP addresses (such as 127.1, 01200034567, 012.1.2.3, 000:0:0000::01, and ::fFFf:127.0.0.1) are improperly categorized as globally routable via isPublic. NOTE: this issue exists because of an incomplete fix for CVE-2023-42282.
A flaw was found in node-ip. The fix for CVE-2023-42282 in the ip package for Node.js was incomplete, and the issue may still be triggered using some IP addresses.
Statement: For CVE-2023-42282, npm does not utilize the bundled code, therefore Red Hat Enterprise Linux is not affected by this vulnerability.
Mitigation: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria co
Debian
CVE-2023-29415: bzip3 - An issue was discovered in libbzip3.a in bzip3 before 1.3.0. A denial of service...
vendor_debian·2023·CVSS 6.5
CVE-2023-29415 [MEDIUM] CVE-2023-29415: bzip3 - An issue was discovered in libbzip3.a in bzip3 before 1.3.0. A denial of service...
An issue was discovered in libbzip3.a in bzip3 before 1.3.0. A denial of service (process hang) can occur with a crafted archive because bzip3 does not follow the required procedure for interacting with libsais.
Scope: local
bookworm: resolved (fixed in 1.2.2-2)
forky: resolved (fixed in 1.2.2-2)
sid: resolved (fixed in 1.2.2-2)
trixie: resolved (fixed in 1.2.2-2)
GHSA
ip SSRF improper categorization in isPublic
ghsa·2024-06-02·CVSS 9.8
CVE-2024-29415 [CRITICAL] CWE-918 ip SSRF improper categorization in isPublic
ip SSRF improper categorization in isPublic
The ip package through 2.0.1 for Node.js might allow SSRF because some IP addresses (such as 127.1, 01200034567, 012.1.2.3, 000:0:0000::01, and ::fFFf:127.0.0.1) are improperly categorized as globally routable via isPublic. NOTE: this issue exists because of an incomplete fix for CVE-2023-42282.
OSV
CVE-2023-29415: An issue was discovered in libbzip3
osv·2023-04-06·CVSS 6.5
CVE-2023-29415 [MEDIUM] CVE-2023-29415: An issue was discovered in libbzip3
An issue was discovered in libbzip3.a in bzip3 before 1.3.0. A denial of service (process hang) can occur with a crafted archive because bzip3 does not follow the required procedure for interacting with libsais.
GHSA
GHSA-x9qg-mxcc-p559: An issue was discovered in libbzip3
ghsa_unreviewed·2023-04-06
CVE-2023-29415 [MEDIUM] GHSA-x9qg-mxcc-p559: An issue was discovered in libbzip3
An issue was discovered in libbzip3.a in bzip3 before 1.3.0. A denial of service (process hang) can occur with a crafted archive because bzip3 does not follow the required procedure for interacting with libsais.
No detection rules found.
No public exploits indexed.
https://github.com/kspalaiologos/bzip3/compare/1.2.3...1.3.0https://github.com/kspalaiologos/bzip3/issues/95https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4JLSE25SV7K2NB6FTFT4UHJOJUHBHYHY/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NA7S7HDUAINOTCSWQZ5LIW756DYY22V2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NMLFV2FJK3CM7NJLVPZI5RUAFQZICPWW/https://security-tracker.debian.org/tracker/CVE-2023-29415https://github.com/kspalaiologos/bzip3/compare/1.2.3...1.3.0https://github.com/kspalaiologos/bzip3/issues/95https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4JLSE25SV7K2NB6FTFT4UHJOJUHBHYHY/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NA7S7HDUAINOTCSWQZ5LIW756DYY22V2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NMLFV2FJK3CM7NJLVPZI5RUAFQZICPWW/https://security-tracker.debian.org/tracker/CVE-2023-29415
2023-04-06
Published