First published: Thu Apr 06 2023(Updated: )
An issue was discovered in libbzip3.a in bzip3 before 1.2.3. There is a crash caused by an invalid memmove in bz3_decode_block.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
bzip3 | <1.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-29420.
The severity of CVE-2023-29420 is medium, with a severity value of 6.5.
The affected software is Bzip3 Project Bzip3 version up to but not including 1.2.3.
The CWE number for CVE-2023-29420 is 119.
Yes, a fix is available. It can be found in the commit titled 'bb06deb85f1c249838eb938e0dab271d4194f8fa' in the bzip3 repository.