Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8jvr-397x-xqh9

Опубликовано: 09 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.2

Описание

bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.

bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.

EPSS

Процентиль: 34%
0.00417
Низкий

8.2 High

CVSS4

Дефекты

CWE-121

Связанные уязвимости

ubuntu
около 2 месяцев назад

bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.

CVSS3: 5.9
redhat
около 2 месяцев назад

bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.

nvd
около 2 месяцев назад

bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.

msrc
около 1 месяца назад

bz2.BZ2Decompressor reuse after error can cause a stack buffer overflow

debian
около 2 месяцев назад

bz2.BZ2Decompressor objects could be reused after a decompression erro ...

EPSS

Процентиль: 34%
0.00417
Низкий

8.2 High

CVSS4

Дефекты

CWE-121