CVE-2023-29416: Medium severity bzip3 vulnerability
Published Apr 6, 2023
·Updated
An issue was discovered in libbzip3.a in bzip3 before 1.3.0. A bz3decodeblock out-of-bounds write can occur with a crafted archive because bzip3 does not follow the required procedure for interacting with libsais.
Affected Software
1 affected component
Bzip3 Project Bzip3<1.3.0
Remediation
Patch Available
Event History
Apr 6, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-29416.
2
What is the severity of CVE-2023-29416?
The severity of CVE-2023-29416 is medium with a severity value of 6.5.
3
What is affected by CVE-2023-29416?
The Bzip3 software version up to exclusive version 1.3.0 is affected by CVE-2023-29416.
4
How can CVE-2023-29416 be exploited?
CVE-2023-29416 can be exploited by using a crafted archive that triggers an out-of-bounds write in the bz3_decode_block function.
5
Is there a fix available for CVE-2023-29416?
Yes, the fix for CVE-2023-29416 can be found in the 1.3.0 version of the Bzip3 software.