First published: Thu Jun 27 2019(Updated: )
<a class="bz_bug_link bz_status_CLOSED bz_closed bz_public " title="CLOSED CURRENTRELEASE - broken links of default index.html" href="show_bug.cgi?id=2">BZ2</a>_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors. Reference: <a href="https://gitlab.com/federicomenaquintero/bzip2/commit/74de1e2e6ffc9d51ef9824db71a8ffee5962cdbc">https://gitlab.com/federicomenaquintero/bzip2/commit/74de1e2e6ffc9d51ef9824db71a8ffee5962cdbc</a>
Affected Software | Affected Version | How to fix |
---|---|---|
bzip2 | <1.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1724459 is considered critical due to an out-of-bounds write vulnerability.
To fix REDHAT-BUG-1724459, update the bzip2 software to version 1.0.6 or later.
REDHAT-BUG-1724459 affects bzip2 versions prior to 1.0.6.
REDHAT-BUG-1724459 can potentially allow an attacker to execute arbitrary code on the affected system.
There are no known workarounds for REDHAT-BUG-1724459 other than upgrading the software.