4.3
CVSSv2

CVE-2009-1884

Published: 19/08/2009 Updated: 13/02/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module prior to 2.018 for Perl allows context-dependent malicious users to cause a denial of service (application hang or crash) via a crafted bzip2 compressed stream that triggers a buffer overflow, a related issue to CVE-2009-1391.

Vulnerable Product Search on Vulmon Subscribe to Product

bzip compress-raw-bzip2

bzip compress-raw-bzip2 2.0.00_10

bzip compress-raw-bzip2 2.0.00_12

bzip compress-raw-bzip2 2.0.00_14

bzip compress-raw-bzip2 2.0.01

bzip compress-raw-bzip2 2.0.02

bzip compress-raw-bzip2 2.0.03

bzip compress-raw-bzip2 2.0.05

bzip compress-raw-bzip2 2.0.06

bzip compress-raw-bzip2 2.0.08

bzip compress-raw-bzip2 2.0.09

bzip compress-raw-bzip2 2.010

bzip compress-raw-bzip2 2.011

bzip compress-raw-bzip2 2.012

bzip compress-raw-bzip2 2.014

bzip compress-raw-bzip2 2.015

Vendor Advisories

Debian Bug report logs - #542777 CVE-2009-1884: Off-by-one error in the bzinflate function in Bzip2xs Package: libcompress-raw-bzip2-perl; Maintainer for libcompress-raw-bzip2-perl is Debian Perl Group <pkg-perl-maintainers@listsaliothdebianorg>; Source for libcompress-raw-bzip2-perl is src:libcompress-raw-bzip2-perl (PTS, build ...