Description
bzlib.c in bzip2 before 1.0.5 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted file that triggers a buffer over-read, as demonstrated by the PROTOS GENOME test suite for Archive Formats.
Published: 2008-03-18
Score: 4.3 Medium
EPSS: 7.7% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2008-1379 bzlib.c in bzip2 before 1.0.5 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted file that triggers a buffer over-read, as demonstrated by the PROTOS GENOME test suite for Archive Formats.
Ubuntu USN Ubuntu USN USN-590-1 bzip2 vulnerability
References
Link Providers
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-004.txt.asc cve-icon cve-icon
http://kb.vmware.com/kb/1006982 cve-icon cve-icon
http://kb.vmware.com/kb/1007198 cve-icon cve-icon
http://kb.vmware.com/kb/1007504 cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2009/Aug/msg00001.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2008-05/msg00000.html cve-icon cve-icon
http://secunia.com/advisories/29410 cve-icon cve-icon
http://secunia.com/advisories/29475 cve-icon cve-icon
http://secunia.com/advisories/29497 cve-icon cve-icon
http://secunia.com/advisories/29506 cve-icon cve-icon
http://secunia.com/advisories/29656 cve-icon cve-icon
http://secunia.com/advisories/29677 cve-icon cve-icon
http://secunia.com/advisories/29698 cve-icon cve-icon
http://secunia.com/advisories/29940 cve-icon cve-icon
http://secunia.com/advisories/31204 cve-icon cve-icon
http://secunia.com/advisories/31869 cve-icon cve-icon
http://secunia.com/advisories/31878 cve-icon cve-icon
http://secunia.com/advisories/36096 cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-200903-40.xml cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-26-241786-1 cve-icon cve-icon
http://support.apple.com/kb/HT3757 cve-icon cve-icon
http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0118 cve-icon cve-icon
http://www.bzip.org/CHANGES cve-icon cve-icon
http://www.cert.fi/haavoittuvuudet/joint-advisory-archive-formats.html cve-icon cve-icon
http://www.ee.oulu.fi/research/ouspg/protos/testing/c10/archive/ cve-icon cve-icon
http://www.gentoo.org/security/en/glsa/glsa-200804-02.xml cve-icon cve-icon
http://www.ipcop.org/index.php?name=News&file=article&sid=40 cve-icon cve-icon
http://www.kb.cert.org/vuls/id/813451 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2008:075 cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2008-0893.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/489968/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/498863/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/28286 cve-icon cve-icon
http://www.securitytracker.com/id?1020867 cve-icon cve-icon
http://www.slackware.org/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.473263 cve-icon cve-icon
http://www.us-cert.gov/cas/techalerts/TA09-218A.html cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/0915 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/2557 cve-icon cve-icon
http://www.vupen.com/english/advisories/2009/2172 cve-icon cve-icon
https://bugs.gentoo.org/attachment.cgi?id=146488&action=view cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/41249 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2008-1372 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10067 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6467 cve-icon cve-icon
https://usn.ubuntu.com/590-1/ cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2008-1372 cve-icon
https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00165.html cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00225.html cve-icon cve-icon
History

No history.

Subscriptions

Bzip Bzip2
Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T08:17:34.837Z

Reserved: 2008-03-18T00:00:00.000Z

Link: CVE-2008-1372

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2008-03-18T21:44:00.000

Modified: 2026-04-23T00:35:47.467

Link: CVE-2008-1372

cve-icon Redhat

Severity : Moderate

Publid Date: 2008-03-18T00:00:00Z

Links: CVE-2008-1372 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses