CVE-2008-1372
bzip2: crash on malformed archive file
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
bzlib.c in bzip2 before 1.0.5 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted file that triggers a buffer over-read, as demonstrated by the PROTOS GENOME test suite for Archive Formats.
El archivo bzlib.c en bzip2 versiones anteriores a 1.0.5, permite a los atacantes remotos asistidos por el usuario causar una denegación de servicio (bloqueo) por medio de un archivo diseñado que activa una lectura excesiva del búfer, como es demostrado por el conjunto de pruebas PROTOS GENOME para Formatos de Archivo.
It was discovered that bzip2 did not correctly handle certain malformed archives. If a user or automated system were tricked into processing a specially crafted bzip2 archive, applications linked against libbz2 could be made to crash, possibly leading to a denial of service.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-03-18 CVE Reserved
- 2008-03-18 CVE Published
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- 2025-05-07 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (48)
URL | Date | SRC |
---|---|---|
http://www.securityfocus.com/bid/28286 | 2024-08-07 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Bzip Search vendor "Bzip" | Bzip2 Search vendor "Bzip" for product "Bzip2" | 0.9 Search vendor "Bzip" for product "Bzip2" and version "0.9" | - |
Affected
| ||||||
Bzip Search vendor "Bzip" | Bzip2 Search vendor "Bzip" for product "Bzip2" | 0.9.5a Search vendor "Bzip" for product "Bzip2" and version "0.9.5a" | - |
Affected
| ||||||
Bzip Search vendor "Bzip" | Bzip2 Search vendor "Bzip" for product "Bzip2" | 0.9.5b Search vendor "Bzip" for product "Bzip2" and version "0.9.5b" | - |
Affected
| ||||||
Bzip Search vendor "Bzip" | Bzip2 Search vendor "Bzip" for product "Bzip2" | 0.9.5c Search vendor "Bzip" for product "Bzip2" and version "0.9.5c" | - |
Affected
| ||||||
Bzip Search vendor "Bzip" | Bzip2 Search vendor "Bzip" for product "Bzip2" | 0.9.5d Search vendor "Bzip" for product "Bzip2" and version "0.9.5d" | - |
Affected
| ||||||
Bzip Search vendor "Bzip" | Bzip2 Search vendor "Bzip" for product "Bzip2" | 0.9_a Search vendor "Bzip" for product "Bzip2" and version "0.9_a" | - |
Affected
| ||||||
Bzip Search vendor "Bzip" | Bzip2 Search vendor "Bzip" for product "Bzip2" | 0.9_b Search vendor "Bzip" for product "Bzip2" and version "0.9_b" | - |
Affected
| ||||||
Bzip Search vendor "Bzip" | Bzip2 Search vendor "Bzip" for product "Bzip2" | 0.9_c Search vendor "Bzip" for product "Bzip2" and version "0.9_c" | - |
Affected
| ||||||
Bzip Search vendor "Bzip" | Bzip2 Search vendor "Bzip" for product "Bzip2" | 1.0 Search vendor "Bzip" for product "Bzip2" and version "1.0" | - |
Affected
| ||||||
Bzip Search vendor "Bzip" | Bzip2 Search vendor "Bzip" for product "Bzip2" | 1.0.1 Search vendor "Bzip" for product "Bzip2" and version "1.0.1" | - |
Affected
| ||||||
Bzip Search vendor "Bzip" | Bzip2 Search vendor "Bzip" for product "Bzip2" | 1.0.2 Search vendor "Bzip" for product "Bzip2" and version "1.0.2" | - |
Affected
| ||||||
Bzip Search vendor "Bzip" | Bzip2 Search vendor "Bzip" for product "Bzip2" | 1.0.3 Search vendor "Bzip" for product "Bzip2" and version "1.0.3" | - |
Affected
|