CVE-2023-29415: Medium severity bzip3 vulnerability
An issue was discovered in libbzip3.a in bzip3 before 1.3.0. A denial of service (process hang) can occur with a crafted archive because bzip3 does not follow the required procedure for interacting with libsais.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability identifier for this issue?
The vulnerability identifier for this issue is CVE-2023-29415.
What is the severity of CVE-2023-29415?
The severity of CVE-2023-29415 is medium with a CVSS score of 6.5.
What is the affected software?
The affected software includes bzip3 versions 1.2.2-2 and 1.3.2-1 on Debian Linux 12.0, as well as Bzip3 Project Bzip3 versions up to 1.3.0.
How can a denial of service (process hang) occur with this vulnerability?
A denial of service (process hang) can occur with this vulnerability by using a crafted archive that does not follow the required procedure for interacting with libsais.
How can I fix CVE-2023-29415?
To fix CVE-2023-29415, update bzip3 to version 1.3.2-1 or apply the necessary patches provided by the vendors.