CVE-2010-0405

Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 before 1.0.6 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted compressed file.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.1 UNKNOWN
NETWORK
HIGH
AV:N/AC:H/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 92%
VendorProductVersion
bzipbzip2
𝑥
≤ 1.0.5
bzipbzip2
0.9
bzipbzip2
0.9.0
bzipbzip2
0.9.0a:a
bzipbzip2
0.9.0b:b
bzipbzip2
0.9.0c:c
bzipbzip2
0.9.5_a:_a
bzipbzip2
0.9.5_b:_b
bzipbzip2
0.9.5_c:_c
bzipbzip2
0.9.5_d:_d
bzipbzip2
0.9.5a:a
bzipbzip2
0.9.5b:b
bzipbzip2
0.9.5c:c
bzipbzip2
0.9.5d:d
bzipbzip2
0.9_a:_a
bzipbzip2
0.9_b:_b
bzipbzip2
0.9_c:_c
bzipbzip2
1.0
bzipbzip2
1.0.1
bzipbzip2
1.0.2
bzipbzip2
1.0.3
bzipbzip2
1.0.4
libzip2libzip2
𝑥
≤ 1.0.5
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
bzip2
bullseye
1.0.8-4
fixed
bookworm
1.0.8-5
fixed
sid
1.0.8-6
fixed
trixie
1.0.8-6
fixed
clamav
bullseye
0.103.10+dfsg-0+deb11u1
fixed
bookworm
1.0.5+dfsg-1~deb12u1
fixed
sid
1.4.1+dfsg-1
fixed
trixie
1.4.1+dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
bzip2
lucid
Fixed 1.0.5-4ubuntu0.1
released
karmic
Fixed 1.0.5-3ubuntu0.1
released
jaunty
Fixed 1.0.5-1ubuntu1.1
released
hardy
Fixed 1.0.4-2ubuntu4.1
released
dapper
Fixed 1.0.3-0ubuntu2.2
released
clamav
lucid
Fixed 0.96.1+dfsg-0ubuntu0.10.04.2
released
karmic
Fixed 0.95.3+dfsg-1ubuntu0.09.10.3
released
jaunty
Fixed 0.95.3+dfsg-1ubuntu0.09.04.3
released
hardy
Fixed 0.95.3+dfsg-1ubuntu0.09.04~hardy2.5
released
dapper
Fixed 0.95.3+dfsg-1ubuntu0.09.04~dapper4.1
released
dpkg
lucid
Fixed 1.15.5.6ubuntu4.3
released
karmic
Fixed 1.15.4ubuntu2.2
released
jaunty
Fixed 1.14.24ubuntu1.2
released
hardy
Fixed 1.14.16.6ubuntu4.2
released
dapper
Fixed 1.13.11ubuntu7.2
released
dump
lucid
Fixed 0.4b42-1ubuntu0.10.04.1
released
karmic
Fixed 0.4b42-1ubuntu0.9.10.1
released
jaunty
Fixed 0.4b41-6ubuntu0.1
released
hardy
Fixed 0.4b41-5ubuntu0.1
released
dapper
Fixed 0.4b41-2ubuntu0.1
released
Common Weakness Enumeration
References