CVE-2010-0405

Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 before 1.0.6 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted compressed file.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.1 UNKNOWN
NETWORK
HIGH
AV:N/AC:H/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 92%
Affected Products (NVD)
VendorProductVersion
bzipbzip2
𝑥
≤ 1.0.5
bzipbzip2
0.9
bzipbzip2
0.9.0
bzipbzip2
0.9.0a:a
bzipbzip2
0.9.0b:b
bzipbzip2
0.9.0c:c
bzipbzip2
0.9.5_a:_a
bzipbzip2
0.9.5_b:_b
bzipbzip2
0.9.5_c:_c
bzipbzip2
0.9.5_d:_d
bzipbzip2
0.9.5a:a
bzipbzip2
0.9.5b:b
bzipbzip2
0.9.5c:c
bzipbzip2
0.9.5d:d
bzipbzip2
0.9_a:_a
bzipbzip2
0.9_b:_b
bzipbzip2
0.9_c:_c
bzipbzip2
1.0
bzipbzip2
1.0.1
bzipbzip2
1.0.2
bzipbzip2
1.0.3
bzipbzip2
1.0.4
libzip2libzip2
𝑥
≤ 1.0.5
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
bzip2
bookworm
1.0.8-5
fixed
bullseye
1.0.8-4
fixed
sid
1.0.8-6
fixed
trixie
1.0.8-6
fixed
clamav
bookworm
1.0.5+dfsg-1~deb12u1
fixed
bullseye
0.103.10+dfsg-0+deb11u1
fixed
sid
1.4.1+dfsg-1
fixed
trixie
1.4.1+dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
bzip2
dapper
Fixed 1.0.3-0ubuntu2.2
released
hardy
Fixed 1.0.4-2ubuntu4.1
released
jaunty
Fixed 1.0.5-1ubuntu1.1
released
karmic
Fixed 1.0.5-3ubuntu0.1
released
lucid
Fixed 1.0.5-4ubuntu0.1
released
clamav
dapper
Fixed 0.95.3+dfsg-1ubuntu0.09.04~dapper4.1
released
hardy
Fixed 0.95.3+dfsg-1ubuntu0.09.04~hardy2.5
released
jaunty
Fixed 0.95.3+dfsg-1ubuntu0.09.04.3
released
karmic
Fixed 0.95.3+dfsg-1ubuntu0.09.10.3
released
lucid
Fixed 0.96.1+dfsg-0ubuntu0.10.04.2
released
dpkg
dapper
Fixed 1.13.11ubuntu7.2
released
hardy
Fixed 1.14.16.6ubuntu4.2
released
jaunty
Fixed 1.14.24ubuntu1.2
released
karmic
Fixed 1.15.4ubuntu2.2
released
lucid
Fixed 1.15.5.6ubuntu4.3
released
dump
dapper
Fixed 0.4b41-2ubuntu0.1
released
hardy
Fixed 0.4b41-5ubuntu0.1
released
jaunty
Fixed 0.4b41-6ubuntu0.1
released
karmic
Fixed 0.4b42-1ubuntu0.9.10.1
released
lucid
Fixed 0.4b42-1ubuntu0.10.04.1
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
bzip2
suse enterprise desktop 15
1.0.6-3.22
fixed
suse enterprise desktop 15 SP1
1.0.6-3.22
fixed
suse enterprise sap 12 SP5
1.0.6-30.8.1
fixed
suse enterprise sap 15
1.0.6-3.22
fixed
suse enterprise sap 15 SP1
1.0.6-3.22
fixed
suse enterprise server 12 SP5
1.0.6-30.8.1
fixed
suse enterprise server 15
1.0.6-3.22
fixed
suse enterprise server 15 SP1
1.0.6-3.22
fixed
bzip2-doc
suse enterprise sap 12 SP5
1.0.6-30.8.1
fixed
suse enterprise server 12 SP5
1.0.6-30.8.1
fixed
clamav
suse enterprise desktop 15
0.100.0-1.17
fixed
suse enterprise desktop 15 SP1
0.100.3-3.9.1
fixed
suse enterprise sap 12 SP5
0.101.3-1.19
fixed
suse enterprise sap 15
0.100.0-1.17
fixed
suse enterprise sap 15 SP1
0.100.3-3.9.1
fixed
suse enterprise server 12 SP5
0.101.3-1.19
fixed
suse enterprise server 15
0.100.0-1.17
fixed
suse enterprise server 15 SP1
0.100.3-3.9.1
fixed
clamav-devel
suse enterprise desktop 15
0.100.0-1.17
fixed
suse enterprise desktop 15 SP1
0.100.3-3.9.1
fixed
suse enterprise sap 15
0.100.0-1.17
fixed
suse enterprise sap 15 SP1
0.100.3-3.9.1
fixed
suse enterprise server 15
0.100.0-1.17
fixed
suse enterprise server 15 SP1
0.100.3-3.9.1
fixed
libbz2-1
suse enterprise desktop 15
1.0.6-3.22
fixed
suse enterprise desktop 15 SP1
1.0.6-3.22
fixed
suse enterprise sap 12 SP5
1.0.6-30.8.1
fixed
suse enterprise sap 15
1.0.6-3.22
fixed
suse enterprise sap 15 SP1
1.0.6-3.22
fixed
suse enterprise server 12 SP5
1.0.6-30.8.1
fixed
suse enterprise server 15
1.0.6-3.22
fixed
suse enterprise server 15 SP1
1.0.6-3.22
fixed
libbz2-1-32bit
suse enterprise desktop 15
1.0.6-3.22
fixed
suse enterprise desktop 15 SP1
1.0.6-3.22
fixed
suse enterprise sap 12 SP5
1.0.6-30.8.1
fixed
suse enterprise sap 15
1.0.6-3.22
fixed
suse enterprise sap 15 SP1
1.0.6-3.22
fixed
suse enterprise server 12 SP5
1.0.6-30.8.1
fixed
suse enterprise server 15
1.0.6-3.22
fixed
suse enterprise server 15 SP1
1.0.6-3.22
fixed
libbz2-devel
suse enterprise desktop 15
1.0.6-3.22
fixed
suse enterprise desktop 15 SP1
1.0.6-3.22
fixed
suse enterprise sap 15
1.0.6-3.22
fixed
suse enterprise sap 15 SP1
1.0.6-3.22
fixed
suse enterprise server 15
1.0.6-3.22
fixed
suse enterprise server 15 SP1
1.0.6-3.22
fixed
libclamav7
suse enterprise desktop 15
0.100.0-1.17
fixed
suse enterprise desktop 15 SP1
0.100.3-3.9.1
fixed
suse enterprise sap 15
0.100.0-1.17
fixed
suse enterprise sap 15 SP1
0.100.3-3.9.1
fixed
suse enterprise server 15
0.100.0-1.17
fixed
suse enterprise server 15 SP1
0.100.3-3.9.1
fixed
libclammspack0
suse enterprise desktop 15
0.100.0-1.17
fixed
suse enterprise desktop 15 SP1
0.100.3-3.9.1
fixed
suse enterprise sap 15
0.100.0-1.17
fixed
suse enterprise sap 15 SP1
0.100.3-3.9.1
fixed
suse enterprise server 15
0.100.0-1.17
fixed
suse enterprise server 15 SP1
0.100.3-3.9.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
bzip2
RHEL 6
0:1.0.5-7.el6_0
fixed
bzip2-devel
RHEL 6
0:1.0.5-7.el6_0
fixed
bzip2-libs
RHEL 6
0:1.0.5-7.el6_0
fixed
Common Weakness Enumeration
References