REDHAT-BUG-1724459: Low severity bzip2 vulnerability
Published Jun 27, 2019
·Updated
BZ2decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.
Reference: https://gitlab.com/federicomenaquintero/bzip2/commit/74de1e2e6ffc9d51ef9824db71a8ffee5962cdbc
Affected Software
1 affected component
Bzip2 bzip2<1.0.6
Event History
Jun 27, 2019
Data Sourced
via Red Hat·07:16 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-1724459?
The severity of REDHAT-BUG-1724459 is considered critical due to an out-of-bounds write vulnerability.
2
How do I fix REDHAT-BUG-1724459?
To fix REDHAT-BUG-1724459, update the bzip2 software to version 1.0.6 or later.
3
What systems are affected by REDHAT-BUG-1724459?
REDHAT-BUG-1724459 affects bzip2 versions prior to 1.0.6.
4
What impact does REDHAT-BUG-1724459 have?
REDHAT-BUG-1724459 can potentially allow an attacker to execute arbitrary code on the affected system.
5
Is there a workaround for REDHAT-BUG-1724459?
There are no known workarounds for REDHAT-BUG-1724459 other than upgrading the software.