CVE-2009-1884

EUVD-2009-1879
Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attackers to cause a denial of service (application hang or crash) via a crafted bzip2 compressed stream that triggers a buffer overflow, a related issue to CVE-2009-1391.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 79%
Affected Products (NVD)
VendorProductVersion
bzipcompress-raw-bzip2
𝑥
≤ 2.017
bzipcompress-raw-bzip2
2.0.00_10:_10
bzipcompress-raw-bzip2
2.0.00_12:_12
bzipcompress-raw-bzip2
2.0.00_14:_14
bzipcompress-raw-bzip2
2.0.01
bzipcompress-raw-bzip2
2.0.02
bzipcompress-raw-bzip2
2.0.03
bzipcompress-raw-bzip2
2.0.05
bzipcompress-raw-bzip2
2.0.06
bzipcompress-raw-bzip2
2.0.08
bzipcompress-raw-bzip2
2.0.09
bzipcompress-raw-bzip2
2.010
bzipcompress-raw-bzip2
2.011
bzipcompress-raw-bzip2
2.012
bzipcompress-raw-bzip2
2.014
bzipcompress-raw-bzip2
2.015
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libcompress-raw-bzip2-perl
bookworm
2.204-1
fixed
bullseye
2.101-1
fixed
sid
2.213-1
fixed
trixie
2.213-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libcompress-raw-bzip2-perl
dapper
dne
hardy
dne
intrepid
ignored
jaunty
ignored
karmic
not-affected
lucid
not-affected
maverick
not-affected
Common Weakness Enumeration