CVE-2009-1884
19.08.2009, 17:30
Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attackers to cause a denial of service (application hang or crash) via a crafted bzip2 compressed stream that triggers a buffer overflow, a related issue to CVE-2009-1391.Enginsight
| Vendor | Product | Version |
|---|---|---|
| bzip | compress-raw-bzip2 | 𝑥 ≤ 2.017 |
| bzip | compress-raw-bzip2 | 2.0.00_10:_10 |
| bzip | compress-raw-bzip2 | 2.0.00_12:_12 |
| bzip | compress-raw-bzip2 | 2.0.00_14:_14 |
| bzip | compress-raw-bzip2 | 2.0.01 |
| bzip | compress-raw-bzip2 | 2.0.02 |
| bzip | compress-raw-bzip2 | 2.0.03 |
| bzip | compress-raw-bzip2 | 2.0.05 |
| bzip | compress-raw-bzip2 | 2.0.06 |
| bzip | compress-raw-bzip2 | 2.0.08 |
| bzip | compress-raw-bzip2 | 2.0.09 |
| bzip | compress-raw-bzip2 | 2.010 |
| bzip | compress-raw-bzip2 | 2.011 |
| bzip | compress-raw-bzip2 | 2.012 |
| bzip | compress-raw-bzip2 | 2.014 |
| bzip | compress-raw-bzip2 | 2.015 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References