CVE-2023-29418: Medium severity bzip3 vulnerability
Published Apr 6, 2023
·Updated
An issue was discovered in libbzip3.a in bzip3 before 1.2.3. There is an xwrite out-of-bounds read.
Affected Software
1 affected component
Bzip3 Project Bzip3<1.2.3
Remediation
Patch Available
Event History
Apr 6, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-29418?
CVE-2023-29418 is a vulnerability in libbzip3.a in bzip3 before version 1.2.3 that allows for an xwrite out-of-bounds read.
2
How severe is CVE-2023-29418?
CVE-2023-29418 has a severity rating of medium with a CVSS score of 6.5.
3
Which software versions are affected by CVE-2023-29418?
Versions up to but excluding 1.2.3 of Bzip3 from the Bzip3 Project are affected by CVE-2023-29418.
4
Is there a fix available for CVE-2023-29418?
Yes, the fix for CVE-2023-29418 is available in version 1.2.3 of Bzip3.
5
Where can I find more information about CVE-2023-29418?
You can find more information about CVE-2023-29418 on the Bzip3 Project's GitHub page and the associated GitHub issues.