CVE-2023-29420: Buffer Overflow
Published Apr 6, 2023
·Updated
An issue was discovered in libbzip3.a in bzip3 before 1.2.3. There is a crash caused by an invalid memmove in bz3decodeblock.
Affected Software
1 affected component
Bzip3 Project Bzip3<1.2.3
Remediation
Patch Available
Event History
Apr 6, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-29420.
2
What is the severity of CVE-2023-29420?
The severity of CVE-2023-29420 is medium, with a severity value of 6.5.
3
What is the affected software?
The affected software is Bzip3 Project Bzip3 version up to but not including 1.2.3.
4
What is the CWE number?
The CWE number for CVE-2023-29420 is 119.
5
Is there a fix available for CVE-2023-29420?
Yes, a fix is available. It can be found in the commit titled 'bb06deb85f1c249838eb938e0dab271d4194f8fa' in the bzip3 repository.