PT-2008-2962 · Bzip2+1 · Bzip2+1

Publicado

2008-03-18

·

Atualizado

2024-06-15

·

CVE-2008-1372

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions bzip2 versions prior to 1.0.5
Description The issue allows user-assisted remote attackers to cause a denial of service, resulting in a crash. This can be triggered by a crafted file that causes a buffer over-read. The PROTOS GENOME test suite for Archive Formats has demonstrated this issue.
Recommendations For versions prior to 1.0.5, update to version 1.0.5 or later to resolve the issue. As a temporary workaround, consider avoiding the use of crafted files that may trigger the buffer over-read until a patch is applied. Restrict access to untrusted archive files to minimize the risk of exploitation.

Exploit

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-1372
OPENSUSE-SU-2024:10667-1
RHSA-2008:0893
RHSA-2008_0893

Produtos afetados

Red Hat
Bzip2