CVE-2016-3189

Published: 06/30/2016 17:59:01
Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2 file, related to block ends set to before the start of the block.
MEDIUM
CVSS v3: 6.5

Status

DocFilters Release Package State Justification Comment
25.1 bzip2 (1.0.8) Not Affected Code Not Reachable vulnerability is in tool that we do not compile
24.4 bzip2 (1.0.8) Not Affected Code Not Reachable vulnerability is in tool that we do not compile
24.4.0 bzip2 (1.0.8) Not Affected Code Not Reachable vulnerability is in tool that we do not compile
24.3 bzip2 (1.0.8) Not Affected Code Not Reachable vulnerability is in tool that we do not compile
24.2.1 bzip2 (1.0.8) Not Affected Code Not Reachable vulnerability is in tool that we do not compile
24.2 bzip2 (1.0.8) Not Affected Code Not Reachable vulnerability is in tool that we do not compile
24.1 bzip2 (1.0.8) Not Affected Code Not Reachable vulnerability is in tool that we do not compile
23.3 bzip2 (1.0.8) Not Affected Code Not Reachable vulnerability is in tool that we do not compile
23.2.1 bzip2 (1.0.6) Not Affected Code Not Reachable vulnerability is in tool that we do not compile
23.2 bzip2 (1.0.6) Not Affected Code Not Reachable vulnerability is in tool that we do not compile
23.1 bzip2 (1.0.6) Not Affected Code Not Reachable vulnerability is in tool that we do not compile
22.4 bzip2 (1.0.6) Not Affected Code Not Reachable vulnerability is in tool that we do not compile
22.3 bzip2 (1.0.6) Needs Triage vulnerability is in tool that we do not compile
22.2 bzip2 (1.0.6) Needs Triage vulnerability is in tool that we do not compile
22.1 bzip2 (1.0.6) Needs Triage vulnerability is in tool that we do not compile
21.11.1 bzip2 (1.0.6) Needs Triage vulnerability is in tool that we do not compile
21.11 bzip2 (1.0.6) Needs Triage vulnerability is in tool that we do not compile
21.8.1 bzip2 (1.0.6) Needs Triage vulnerability is in tool that we do not compile
21.8 bzip2 (1.0.6) Needs Triage vulnerability is in tool that we do not compile
21.5.1 bzip2 (1.0.6) Needs Triage vulnerability is in tool that we do not compile
21.5.0 bzip2 (1.0.6) Needs Triage vulnerability is in tool that we do not compile
21.2.0 bzip2 (1.0.6) Needs Triage vulnerability is in tool that we do not compile
11.4.20 bzip2 (1.0.6) Needs Triage vulnerability is in tool that we do not compile
11.4.19.3667 bzip2 (1.0.6) Needs Triage vulnerability is in tool that we do not compile
11.4.18.3599 bzip2 (1.0.6) Needs Triage vulnerability is in tool that we do not compile
11.4.17 bzip2 (1.0.6) Needs Triage vulnerability is in tool that we do not compile
11.4.16.3445 bzip2 (1.0.6) Needs Triage vulnerability is in tool that we do not compile
11.4.15.3368 bzip2 (1.0.6) Needs Triage vulnerability is in tool that we do not compile
11.4.14.3263 bzip2 (1.0.6) Needs Triage vulnerability is in tool that we do not compile
11.4.13.3179 bzip2 (1.0.6) Needs Triage vulnerability is in tool that we do not compile
11.4.12.3054 bzip2 (1.0.6) Needs Triage vulnerability is in tool that we do not compile
11.4.11.3040 bzip2 (1.0.6) Needs Triage vulnerability is in tool that we do not compile
11.4.11.2990 bzip2 (1.0.6) Needs Triage vulnerability is in tool that we do not compile
11.4.10.2934 bzip2 (1.0.6) Needs Triage vulnerability is in tool that we do not compile
11.4.9.2878 bzip2 (1.0.6) Needs Triage vulnerability is in tool that we do not compile
11.4.8.2822 bzip2 (1.0.6) Needs Triage vulnerability is in tool that we do not compile

Severity score breakdown

Attack Complexity
LOW
Attack Vector
NETWORK
Availability Impact
HIGH
Base Score
6.5
Base Severity
MEDIUM
Confidentiality Impact
NONE
Integrity Impact
NONE
Privileges Required
NONE
Scope
UNCHANGED
User Interaction
REQUIRED
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Version
3.1

References