Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2010-0405

Опубликовано: 28 сент. 2010
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5.1

Описание

Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 before 1.0.6 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted compressed file.

РелизСтатусПримечание
dapper

released

1.0.3-0ubuntu2.2
devel

released

1.0.5-4ubuntu1
hardy

released

1.0.4-2ubuntu4.1
jaunty

released

1.0.5-1ubuntu1.1
karmic

released

1.0.5-3ubuntu0.1
lucid

released

1.0.5-4ubuntu0.1
upstream

released

1.0.6

Показывать по

РелизСтатусПримечание
dapper

released

0.95.3+dfsg-1ubuntu0.09.04~dapper4.1
devel

released

1.0.5-4ubuntu1
hardy

released

0.95.3+dfsg-1ubuntu0.09.04~hardy2.5
jaunty

released

0.95.3+dfsg-1ubuntu0.09.04.3
karmic

released

0.95.3+dfsg-1ubuntu0.09.10.3
lucid

released

0.96.1+dfsg-0ubuntu0.10.04.2
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

released

1.13.11ubuntu7.2
devel

not-affected

uses dynamic system libbz2
hardy

released

1.14.16.6ubuntu4.2
jaunty

released

1.14.24ubuntu1.2
karmic

released

1.15.4ubuntu2.2
lucid

released

1.15.5.6ubuntu4.3
upstream

not-affected

Показывать по

РелизСтатусПримечание
dapper

released

0.4b41-2ubuntu0.1
devel

released

0.4b43-1build1
hardy

released

0.4b41-5ubuntu0.1
jaunty

released

0.4b41-6ubuntu0.1
karmic

released

0.4b42-1ubuntu0.9.10.1
lucid

released

0.4b42-1ubuntu0.10.04.1
upstream

not-affected

Показывать по

EPSS

Процентиль: 92%
0.0921
Низкий

5.1 Medium

CVSS2

Связанные уязвимости

redhat
почти 15 лет назад

Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 before 1.0.6 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted compressed file.

nvd
больше 14 лет назад

Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 before 1.0.6 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted compressed file.

debian
больше 14 лет назад

Integer overflow in the BZ2_decompress function in decompress.c in bzi ...

github
около 3 лет назад

Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 before 1.0.6 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted compressed file.

oracle-oval
больше 14 лет назад

ELSA-2010-0858: bzip2 security update (IMPORTANT)

EPSS

Процентиль: 92%
0.0921
Низкий

5.1 Medium

CVSS2

Уязвимость CVE-2010-0405