CVE-2008-1372

bzlib.c in bzip2 before 1.0.5 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted file that triggers a buffer over-read, as demonstrated by the PROTOS GENOME test suite for Archive Formats.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
VendorProductVersion
bzipbzip2
0.9
bzipbzip2
0.9.5a:a
bzipbzip2
0.9.5b:b
bzipbzip2
0.9.5c:c
bzipbzip2
0.9.5d:d
bzipbzip2
0.9_a:_a
bzipbzip2
0.9_b:_b
bzipbzip2
0.9_c:_c
bzipbzip2
1.0
bzipbzip2
1.0.1
bzipbzip2
1.0.2
bzipbzip2
1.0.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
bzip2
bullseye
1.0.8-4
fixed
etch
no-dsa
bookworm
1.0.8-5
fixed
sid
1.0.8-6
fixed
trixie
1.0.8-6
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
bzip2
gutsy
Fixed 1.0.4-0ubuntu2.1
released
feisty
Fixed 1.0.3-6ubuntu0.1
released
edgy
Fixed 1.0.3-3ubuntu0.1
released
dapper
Fixed 1.0.3-0ubuntu2.1
released
References