// For flags

CVE-2010-0405

bzip2: integer overflow flaw in BZ2_decompress

Severity Score

5.1
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 before 1.0.6 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted compressed file.

Desbordamiento de enteros en la función BZ2_decompress en decompress.c en bzip2 y libbzip2 anterior v1.0.6 permite a atacantes dependientes del contexto causar una denegación de servicio (caída aplicación) o probablemente ejecutar código de su elección a través de ficheros comprimidos manipulados.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2010-01-27 CVE Reserved
  • 2010-09-21 CVE Published
  • 2023-11-08 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-189: Numeric Errors
  • CWE-190: Integer Overflow or Wraparound
CAPEC
References (36)
URL Tag Source
http://blogs.sun.com/security/entry/cve_2010_0405_integer_overflow X_refsource_confirm
http://git.clamav.net/gitweb?p=clamav-devel.git%3Ba=blob_plain%3Bf=ChangeLog%3Bhb=clamav-0.96.3 X_refsource_confirm
http://marc.info/?l=oss-security&m=128506868510655&w=2 Mailing List
http://secunia.com/advisories/41505 Third Party Advisory
http://secunia.com/advisories/42350 Third Party Advisory
http://secunia.com/advisories/42404 Third Party Advisory
http://secunia.com/advisories/42405 Third Party Advisory
http://secunia.com/advisories/42529 Third Party Advisory
http://secunia.com/advisories/42530 Third Party Advisory
http://secunia.com/advisories/48378 Third Party Advisory
http://support.apple.com/kb/HT4581 X_refsource_confirm
http://www.bzip.org X_refsource_confirm
http://www.securityfocus.com/archive/1/515055/100/0/threaded Mailing List
http://www.vmware.com/security/advisories/VMSA-2010-0019.html X_refsource_confirm
http://www.vupen.com/english/advisories/2010/2455 Vdb Entry
http://www.vupen.com/english/advisories/2010/3043 Vdb Entry
http://www.vupen.com/english/advisories/2010/3052 Vdb Entry
http://www.vupen.com/english/advisories/2010/3073 Vdb Entry
http://www.vupen.com/english/advisories/2010/3126 Vdb Entry
http://www.vupen.com/english/advisories/2010/3127 Vdb Entry
http://xorl.wordpress.com/2010/09/21/cve-2010-0405-bzip2-integer-overflow X_refsource_confirm
https://wwws.clamav.net/bugzilla/show_bug.cgi?id=2230 X_refsource_confirm
https://wwws.clamav.net/bugzilla/show_bug.cgi?id=2231 X_refsource_confirm
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Bzip
Search vendor "Bzip"
Bzip2
Search vendor "Bzip" for product "Bzip2"
<= 1.0.5
Search vendor "Bzip" for product "Bzip2" and version " <= 1.0.5"
-
Affected
Bzip
Search vendor "Bzip"
Bzip2
Search vendor "Bzip" for product "Bzip2"
0.9
Search vendor "Bzip" for product "Bzip2" and version "0.9"
-
Affected
Bzip
Search vendor "Bzip"
Bzip2
Search vendor "Bzip" for product "Bzip2"
0.9.0
Search vendor "Bzip" for product "Bzip2" and version "0.9.0"
-
Affected
Bzip
Search vendor "Bzip"
Bzip2
Search vendor "Bzip" for product "Bzip2"
0.9.0a
Search vendor "Bzip" for product "Bzip2" and version "0.9.0a"
-
Affected
Bzip
Search vendor "Bzip"
Bzip2
Search vendor "Bzip" for product "Bzip2"
0.9.0b
Search vendor "Bzip" for product "Bzip2" and version "0.9.0b"
-
Affected
Bzip
Search vendor "Bzip"
Bzip2
Search vendor "Bzip" for product "Bzip2"
0.9.0c
Search vendor "Bzip" for product "Bzip2" and version "0.9.0c"
-
Affected
Bzip
Search vendor "Bzip"
Bzip2
Search vendor "Bzip" for product "Bzip2"
0.9.5_a
Search vendor "Bzip" for product "Bzip2" and version "0.9.5_a"
-
Affected
Bzip
Search vendor "Bzip"
Bzip2
Search vendor "Bzip" for product "Bzip2"
0.9.5_b
Search vendor "Bzip" for product "Bzip2" and version "0.9.5_b"
-
Affected
Bzip
Search vendor "Bzip"
Bzip2
Search vendor "Bzip" for product "Bzip2"
0.9.5_c
Search vendor "Bzip" for product "Bzip2" and version "0.9.5_c"
-
Affected
Bzip
Search vendor "Bzip"
Bzip2
Search vendor "Bzip" for product "Bzip2"
0.9.5_d
Search vendor "Bzip" for product "Bzip2" and version "0.9.5_d"
-
Affected
Bzip
Search vendor "Bzip"
Bzip2
Search vendor "Bzip" for product "Bzip2"
0.9.5a
Search vendor "Bzip" for product "Bzip2" and version "0.9.5a"
-
Affected
Bzip
Search vendor "Bzip"
Bzip2
Search vendor "Bzip" for product "Bzip2"
0.9.5b
Search vendor "Bzip" for product "Bzip2" and version "0.9.5b"
-
Affected
Bzip
Search vendor "Bzip"
Bzip2
Search vendor "Bzip" for product "Bzip2"
0.9.5c
Search vendor "Bzip" for product "Bzip2" and version "0.9.5c"
-
Affected
Bzip
Search vendor "Bzip"
Bzip2
Search vendor "Bzip" for product "Bzip2"
0.9.5d
Search vendor "Bzip" for product "Bzip2" and version "0.9.5d"
-
Affected
Bzip
Search vendor "Bzip"
Bzip2
Search vendor "Bzip" for product "Bzip2"
0.9_a
Search vendor "Bzip" for product "Bzip2" and version "0.9_a"
-
Affected
Bzip
Search vendor "Bzip"
Bzip2
Search vendor "Bzip" for product "Bzip2"
0.9_b
Search vendor "Bzip" for product "Bzip2" and version "0.9_b"
-
Affected
Bzip
Search vendor "Bzip"
Bzip2
Search vendor "Bzip" for product "Bzip2"
0.9_c
Search vendor "Bzip" for product "Bzip2" and version "0.9_c"
-
Affected
Bzip
Search vendor "Bzip"
Bzip2
Search vendor "Bzip" for product "Bzip2"
1.0
Search vendor "Bzip" for product "Bzip2" and version "1.0"
-
Affected
Bzip
Search vendor "Bzip"
Bzip2
Search vendor "Bzip" for product "Bzip2"
1.0.1
Search vendor "Bzip" for product "Bzip2" and version "1.0.1"
-
Affected
Bzip
Search vendor "Bzip"
Bzip2
Search vendor "Bzip" for product "Bzip2"
1.0.2
Search vendor "Bzip" for product "Bzip2" and version "1.0.2"
-
Affected
Bzip
Search vendor "Bzip"
Bzip2
Search vendor "Bzip" for product "Bzip2"
1.0.3
Search vendor "Bzip" for product "Bzip2" and version "1.0.3"
-
Affected
Bzip
Search vendor "Bzip"
Bzip2
Search vendor "Bzip" for product "Bzip2"
1.0.4
Search vendor "Bzip" for product "Bzip2" and version "1.0.4"
-
Affected
Libzip2
Search vendor "Libzip2"
Libzip2
Search vendor "Libzip2" for product "Libzip2"
<= 1.0.5
Search vendor "Libzip2" for product "Libzip2" and version " <= 1.0.5"
-
Affected