Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-1884

Опубликовано: 19 авг. 2009
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attackers to cause a denial of service (application hang or crash) via a crafted bzip2 compressed stream that triggers a buffer overflow, a related issue to CVE-2009-1391.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:bzip:compress-raw-bzip2:*:*:*:*:*:*:*:*
Версия до 2.017 (включая)
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.00_10:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.00_12:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.00_14:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.01:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.02:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.03:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.05:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.06:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.08:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.09:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.010:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.011:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.012:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.014:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.015:*:*:*:*:*:*:*
cpe:2.3:a:perl:perl:*:*:*:*:*:*:*:*

EPSS

Процентиль: 79%
0.01263
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-189

Связанные уязвимости

ubuntu
больше 16 лет назад

Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attackers to cause a denial of service (application hang or crash) via a crafted bzip2 compressed stream that triggers a buffer overflow, a related issue to CVE-2009-1391.

redhat
больше 16 лет назад

Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attackers to cause a denial of service (application hang or crash) via a crafted bzip2 compressed stream that triggers a buffer overflow, a related issue to CVE-2009-1391.

debian
больше 16 лет назад

Off-by-one error in the bzinflate function in Bzip2.xs in the Compress ...

github
почти 4 года назад

Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attackers to cause a denial of service (application hang or crash) via a crafted bzip2 compressed stream that triggers a buffer overflow, a related issue to CVE-2009-1391.

EPSS

Процентиль: 79%
0.01263
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-189