CVE-2008-1372

EUVD-2008-1379
bzlib.c in bzip2 before 1.0.5 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted file that triggers a buffer over-read, as demonstrated by the PROTOS GENOME test suite for Archive Formats.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
Affected Products (NVD)
VendorProductVersion
bzipbzip2
0.9
bzipbzip2
0.9.5a:a
bzipbzip2
0.9.5b:b
bzipbzip2
0.9.5c:c
bzipbzip2
0.9.5d:d
bzipbzip2
0.9_a:_a
bzipbzip2
0.9_b:_b
bzipbzip2
0.9_c:_c
bzipbzip2
1.0
bzipbzip2
1.0.1
bzipbzip2
1.0.2
bzipbzip2
1.0.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
bzip2
bookworm
1.0.8-5
fixed
bullseye
1.0.8-4
fixed
etch
no-dsa
sid
1.0.8-6
fixed
trixie
1.0.8-6
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
bzip2
dapper
Fixed 1.0.3-0ubuntu2.1
released
edgy
Fixed 1.0.3-3ubuntu0.1
released
feisty
Fixed 1.0.3-6ubuntu0.1
released
gutsy
Fixed 1.0.4-0ubuntu2.1
released
References