CVE-2010-0405
28.09.2010, 18:00
Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 before 1.0.6 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted compressed file.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| bzip | bzip2 | 𝑥 ≤ 1.0.5 |
| bzip | bzip2 | 0.9 |
| bzip | bzip2 | 0.9.0 |
| bzip | bzip2 | 0.9.0a:a |
| bzip | bzip2 | 0.9.0b:b |
| bzip | bzip2 | 0.9.0c:c |
| bzip | bzip2 | 0.9.5_a:_a |
| bzip | bzip2 | 0.9.5_b:_b |
| bzip | bzip2 | 0.9.5_c:_c |
| bzip | bzip2 | 0.9.5_d:_d |
| bzip | bzip2 | 0.9.5a:a |
| bzip | bzip2 | 0.9.5b:b |
| bzip | bzip2 | 0.9.5c:c |
| bzip | bzip2 | 0.9.5d:d |
| bzip | bzip2 | 0.9_a:_a |
| bzip | bzip2 | 0.9_b:_b |
| bzip | bzip2 | 0.9_c:_c |
| bzip | bzip2 | 1.0 |
| bzip | bzip2 | 1.0.1 |
| bzip | bzip2 | 1.0.2 |
| bzip | bzip2 | 1.0.3 |
| bzip | bzip2 | 1.0.4 |
| libzip2 | libzip2 | 𝑥 ≤ 1.0.5 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| bzip2 |
| ||||||||||
| clamav |
| ||||||||||
| dpkg |
| ||||||||||
| dump |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| bzip2 |
| ||||||||||||||||
| bzip2-doc |
| ||||||||||||||||
| clamav |
| ||||||||||||||||
| clamav-devel |
| ||||||||||||||||
| libbz2-1 |
| ||||||||||||||||
| libbz2-1-32bit |
| ||||||||||||||||
| libbz2-devel |
| ||||||||||||||||
| libclamav7 |
| ||||||||||||||||
| libclammspack0 |
|
Red Hat Enterprise Linux Releases
Common Weakness Enumeration
References