6.5
CVSSv3

CVE-2023-29417

Published: 06/04/2023 Updated: 17/05/2024
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

An issue exists in libbzip3.a in bzip3 1.2.2. There is a bz3_decompress out-of-bounds read in certain situations where buffers passed to bzip3 do not contain enough space to be filled with decompressed data. NOTE: the vendor's perspective is that the observed behavior can only occur for a contract violation, and thus the report is invalid.

Vulnerable Product Search on Vulmon Subscribe to Product

bzip3 project bzip3 1.2.2