CVE Vulnerabilities

CVE-2010-0405

Published: Sep 28, 2010 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
5.1 IMPORTANT
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 before 1.0.6 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted compressed file.

Affected Software

Name Vendor Start Version End Version
Bzip2 Bzip * 1.0.5 (including)
Bzip2 Bzip 0.9 (including) 0.9 (including)
Bzip2 Bzip 0.9.0 (including) 0.9.0 (including)
Bzip2 Bzip 0.9.0a (including) 0.9.0a (including)
Bzip2 Bzip 0.9.0b (including) 0.9.0b (including)
Bzip2 Bzip 0.9.0c (including) 0.9.0c (including)
Bzip2 Bzip 0.9.5_a (including) 0.9.5_a (including)
Bzip2 Bzip 0.9.5_b (including) 0.9.5_b (including)
Bzip2 Bzip 0.9.5_c (including) 0.9.5_c (including)
Bzip2 Bzip 0.9.5_d (including) 0.9.5_d (including)
Bzip2 Bzip 0.9.5a (including) 0.9.5a (including)
Bzip2 Bzip 0.9.5b (including) 0.9.5b (including)
Bzip2 Bzip 0.9.5c (including) 0.9.5c (including)
Bzip2 Bzip 0.9.5d (including) 0.9.5d (including)
Bzip2 Bzip 0.9_a (including) 0.9_a (including)
Bzip2 Bzip 0.9_b (including) 0.9_b (including)
Bzip2 Bzip 0.9_c (including) 0.9_c (including)
Bzip2 Bzip 1.0 (including) 1.0 (including)
Bzip2 Bzip 1.0.1 (including) 1.0.1 (including)
Bzip2 Bzip 1.0.2 (including) 1.0.2 (including)
Bzip2 Bzip 1.0.3 (including) 1.0.3 (including)
Bzip2 Bzip 1.0.4 (including) 1.0.4 (including)
Libzip2 Libzip2 * 1.0.5 (including)
Red Hat Enterprise Linux 3 RedHat bzip2-0:1.0.2-14.EL3 *
Red Hat Enterprise Linux 4 RedHat bzip2-0:1.0.2-16.el4_8 *
Red Hat Enterprise Linux 5 RedHat bzip2-0:1.0.3-6.el5_5 *
Red Hat Enterprise Linux 6 RedHat bzip2-0:1.0.5-7.el6_0 *
Bzip2 Ubuntu dapper *
Bzip2 Ubuntu devel *
Bzip2 Ubuntu hardy *
Bzip2 Ubuntu jaunty *
Bzip2 Ubuntu karmic *
Bzip2 Ubuntu lucid *
Bzip2 Ubuntu upstream *
Clamav Ubuntu dapper *
Clamav Ubuntu devel *
Clamav Ubuntu hardy *
Clamav Ubuntu jaunty *
Clamav Ubuntu karmic *
Clamav Ubuntu lucid *
Dpkg Ubuntu dapper *
Dpkg Ubuntu hardy *
Dpkg Ubuntu jaunty *
Dpkg Ubuntu karmic *
Dpkg Ubuntu lucid *
Dump Ubuntu dapper *
Dump Ubuntu devel *
Dump Ubuntu hardy *
Dump Ubuntu jaunty *
Dump Ubuntu karmic *
Dump Ubuntu lucid *

References