Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2008-1372

bzlib.c in bzip2 before 1.0.5 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted file that triggers a buffer over-read, as demonstrated by the PROTOS GENOME test suite for Archive Formats.

  • Published: Mar 18, 2008
  • Updated: Apr 13, 2023
  • CVE: CVE-2008-1372
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 4.3
  • AV:N/AC:M/Au:N/C:N/I:N/A:P

CWEs:

Software From Fixed in
bzip / bzip2 1.0 1.0.x
bzip / bzip2 0.9_a 0.9_a.x
bzip / bzip2 0.9.5d 0.9.5d.x
bzip / bzip2 0.9_c 0.9_c.x
bzip / bzip2 1.0.3 1.0.3.x
bzip / bzip2 1.0.2 1.0.2.x
bzip / bzip2 0.9.5a 0.9.5a.x
bzip / bzip2 0.9.5b 0.9.5b.x
bzip / bzip2 0.9 0.9.x
bzip / bzip2 1.0.1 1.0.1.x
bzip / bzip2 0.9.5c 0.9.5c.x
bzip / bzip2 0.9_b 0.9_b.x