CVE-2019-12900

Published: 06/19/2019 23:15:09
BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.
CRITICAL
CVSS v3: 9.8

Status

DocFilters Release Package State Justification Comment
25.1 bzip2 (1.0.8) Not Affected Code Not Present fixed in bzip2 1.0.8
24.4 bzip2 (1.0.8) Not Affected Code Not Present fixed in bzip2 1.0.8
24.4.0 bzip2 (1.0.8) Not Affected Code Not Present fixed in bzip2 1.0.8
24.3 bzip2 (1.0.8) Not Affected Code Not Present fixed in bzip2 1.0.8
24.2.1 bzip2 (1.0.8) Not Affected Code Not Present fixed in bzip2 1.0.8
24.2 bzip2 (1.0.8) Not Affected Code Not Present fixed in bzip2 1.0.8
24.1 bzip2 (1.0.8) Not Affected Code Not Present fixed in bzip2 1.0.8
23.3 bzip2 (1.0.8) Not Affected Code Not Present fixed in bzip2 1.0.8
23.2.1 bzip2 (1.0.6) Resolved Code Not Present Patched applied from https://sourceware.org/git/?p=bzip2.git;a=commit;h=b07b105d1b66e32760095e3602261738443b9e13
23.2 bzip2 (1.0.6) Resolved Code Not Present Patched applied from https://sourceware.org/git/?p=bzip2.git;a=commit;h=b07b105d1b66e32760095e3602261738443b9e13
23.1 bzip2 (1.0.6) Resolved Code Not Present Patched applied from https://sourceware.org/git/?p=bzip2.git;a=commit;h=b07b105d1b66e32760095e3602261738443b9e13
22.4 bzip2 (1.0.6) Resolved Code Not Present Patched applied from https://sourceware.org/git/?p=bzip2.git;a=commit;h=b07b105d1b66e32760095e3602261738443b9e13
22.3 bzip2 (1.0.6) Resolved patched (debian) 2019-11-06
22.2 bzip2 (1.0.6) Resolved patched (debian) 2019-11-06
22.1 bzip2 (1.0.6) Resolved patched (debian) 2019-11-06
21.11.1 bzip2 (1.0.6) Resolved patched (debian) 2019-11-06
21.11 bzip2 (1.0.6) Resolved patched (debian) 2019-11-06
21.8.1 bzip2 (1.0.6) Resolved patched (debian) 2019-11-06
21.8 bzip2 (1.0.6) Resolved patched (debian) 2019-11-06
21.5.1 bzip2 (1.0.6) Resolved patched (debian) 2019-11-06
21.5.0 bzip2 (1.0.6) Resolved patched (debian) 2019-11-06
21.2.0 bzip2 (1.0.6) Resolved patched (debian) 2019-11-06
11.4.20 bzip2 (1.0.6) Resolved patched (debian) 2019-11-06
11.4.19.3667 bzip2 (1.0.6) Resolved patched (debian) 2019-11-06
11.4.18.3599 bzip2 (1.0.6) Resolved patched (debian) 2019-11-06
11.4.17 bzip2 (1.0.6) Resolved patched (debian) 2019-11-06
11.4.16.3445 bzip2 (1.0.6) Resolved patched (debian) 2019-11-06
11.4.15.3368 bzip2 (1.0.6) Resolved patched (debian) 2019-11-06
11.4.14.3263 bzip2 (1.0.6) Needs Triage
11.4.13.3179 bzip2 (1.0.6) Needs Triage
11.4.12.3054 bzip2 (1.0.6) Needs Triage
11.4.11.3040 bzip2 (1.0.6) Needs Triage
11.4.11.2990 bzip2 (1.0.6) Needs Triage
11.4.10.2934 bzip2 (1.0.6) Needs Triage
11.4.9.2878 bzip2 (1.0.6) Needs Triage
11.4.8.2822 bzip2 (1.0.6) Needs Triage

Severity score breakdown

Attack Complexity
LOW
Attack Vector
NETWORK
Availability Impact
HIGH
Base Score
9.8
Base Severity
CRITICAL
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Privileges Required
NONE
Scope
UNCHANGED
User Interaction
NONE
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Version
3.1

References