Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-12900

Опубликовано: 15 нояб. 2024
Источник: redhat
CVSS3: 4.4
EPSS Низкий

Описание

BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.

A data integrity error was found in the bzip2 (User-space package) functionality when decompressing. This issue occurs when a user decompresses a particular kind of .bz2 files. A local user could get unexpected results (or corrupted data) as result of decompressing these files.

Отчет

This vulnerability only causes failure to decompress when using the package bzip2 functionality. There is no known vector of attack (apart of possibility that some of the older archives compressed with bzip2 could become unaccessible if still buggy version of bzip2 being used to decompress). This bug has been fixed in upstream with multiple iterations.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7bzip2Out of support scope
Red Hat Enterprise Linux 8bzip2FixedRHSA-2024:892206.11.2024
Red Hat Enterprise Linux 8bzip2FixedRHSA-2025:073328.01.2025
Red Hat Enterprise Linux 9bzip2FixedRHSA-2025:092504.02.2025
Red Hat Enterprise Linux 9bzip2FixedRHSA-2025:092504.02.2025
Red Hat Enterprise Linux 9.4 Extended Update Supportbzip2FixedRHSA-2024:1080304.12.2024
RHINT Camel-K 1.10.9FixedRHSA-2025:115406.02.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1214
https://bugzilla.redhat.com/show_bug.cgi?id=2332075bzip2: bzip2: Data integrity error when decompressing (with data integrity tests fail).

EPSS

Процентиль: 78%
0.01237
Низкий

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 6 лет назад

BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.

CVSS3: 9.8
nvd
почти 6 лет назад

BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.

CVSS3: 9.8
msrc
почти 5 лет назад

Описание отсутствует

CVSS3: 9.8
debian
почти 6 лет назад

BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bo ...

suse-cvrf
почти 6 лет назад

Security update for bzip2

EPSS

Процентиль: 78%
0.01237
Низкий

4.4 Medium

CVSS3