Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attackers to cause a denial of service (application hang or crash) via a crafted bzip2 compressed stream that triggers a buffer overflow, a related issue to CVE-2009-1391.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Compress-raw-bzip2 | Bzip | * | 2.017 (including) |
Compress-raw-bzip2 | Bzip | 2.0.00_10 (including) | 2.0.00_10 (including) |
Compress-raw-bzip2 | Bzip | 2.0.00_12 (including) | 2.0.00_12 (including) |
Compress-raw-bzip2 | Bzip | 2.0.00_14 (including) | 2.0.00_14 (including) |
Compress-raw-bzip2 | Bzip | 2.0.01 (including) | 2.0.01 (including) |
Compress-raw-bzip2 | Bzip | 2.0.02 (including) | 2.0.02 (including) |
Compress-raw-bzip2 | Bzip | 2.0.03 (including) | 2.0.03 (including) |
Compress-raw-bzip2 | Bzip | 2.0.05 (including) | 2.0.05 (including) |
Compress-raw-bzip2 | Bzip | 2.0.06 (including) | 2.0.06 (including) |
Compress-raw-bzip2 | Bzip | 2.0.08 (including) | 2.0.08 (including) |
Compress-raw-bzip2 | Bzip | 2.0.09 (including) | 2.0.09 (including) |
Compress-raw-bzip2 | Bzip | 2.010 (including) | 2.010 (including) |
Compress-raw-bzip2 | Bzip | 2.011 (including) | 2.011 (including) |
Compress-raw-bzip2 | Bzip | 2.012 (including) | 2.012 (including) |
Compress-raw-bzip2 | Bzip | 2.014 (including) | 2.014 (including) |
Compress-raw-bzip2 | Bzip | 2.015 (including) | 2.015 (including) |
Libcompress-raw-bzip2-perl | Ubuntu | intrepid | * |
Libcompress-raw-bzip2-perl | Ubuntu | jaunty | * |
Libcompress-raw-bzip2-perl | Ubuntu | upstream | * |