CVE-2023-29421: High severity bzip3 vulnerability
An issue was discovered in libbzip3.a in bzip3 before 1.2.3. There is an out-of-bounds write in bz3decodeblock.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-29421?
CVE-2023-29421 is a vulnerability discovered in libbzip3.a in bzip3 before version 1.2.3, which allows for an out-of-bounds write in bz3_decode_block.
What is the severity of CVE-2023-29421?
The severity of CVE-2023-29421 is considered high with a severity score of 8.8.
What software is affected by CVE-2023-29421?
The software affected by CVE-2023-29421 is Bzip3 version up to but excluding 1.2.3.
How can I fix CVE-2023-29421?
To fix CVE-2023-29421, update your Bzip3 software to version 1.2.3 or later.
Where can I find more information about CVE-2023-29421?
You can find more information about CVE-2023-29421 on the following references: [GitHub: Compare 1.2.2...1.2.3](https://github.com/kspalaiologos/bzip3/compare/1.2.2...1.2.3), [GitHub: Issue #94](https://github.com/kspalaiologos/bzip3/issues/94), [Fedora Project Mailing List](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4JLSE25SV7K2NB6FTFT4UHJOJUHBHYHY/).