Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-3189

Опубликовано: 20 июн. 2016
Источник: redhat
CVSS2: 4.3
EPSS Средний

Описание

Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2 file, related to block ends set to before the start of the block.

A use-after-free flaw was found in bzip2recover, leading to a null pointer dereference, or a write to a closed file descriptor. An attacker could use this flaw by sending a specially crafted bzip2 file to recover and force the program to crash.

Отчет

Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5bzip2Will not fix
Red Hat Enterprise Linux 6bzip2Will not fix
Red Hat Enterprise Linux 7bzip2Will not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1319648bzip2: heap use after free in bzip2recover

EPSS

Процентиль: 94%
0.15466
Средний

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 9 лет назад

Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2 file, related to block ends set to before the start of the block.

CVSS3: 6.5
nvd
почти 9 лет назад

Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2 file, related to block ends set to before the start of the block.

CVSS3: 6.5
msrc
почти 5 лет назад

Описание отсутствует

CVSS3: 6.5
debian
почти 9 лет назад

Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows rem ...

suse-cvrf
около 6 лет назад

Security update for bzip2

EPSS

Процентиль: 94%
0.15466
Средний

4.3 Medium

CVSS2