Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 prior to 1.0.6 allows context-dependent malicious users to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted compressed file.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
bzip bzip2 1.0 |
||
bzip bzip2 0.9.5_a |
||
bzip bzip2 0.9.5_d |
||
bzip bzip2 0.9.5_c |
||
bzip bzip2 0.9_a |
||
bzip bzip2 0.9.5d |
||
bzip bzip2 0.9.0a |
||
bzip bzip2 0.9.0 |
||
bzip bzip2 0.9_c |
||
bzip bzip2 1.0.3 |
||
bzip bzip2 1.0.2 |
||
bzip bzip2 0.9.5a |
||
bzip bzip2 0.9.5b |
||
libzip2 libzip2 |
||
bzip bzip2 0.9.0c |
||
bzip bzip2 0.9 |
||
bzip bzip2 1.0.1 |
||
bzip bzip2 0.9.5c |
||
bzip bzip2 0.9_b |
||
bzip bzip2 0.9.5_b |
||
bzip bzip2 1.0.4 |
||
bzip bzip2 0.9.0b |
||
bzip bzip2 |