First published: Mon Sep 20 2010(Updated: )
bzip2 is a freely available, high-quality data compressor. It provides both<br>standalone compression and decompression utilities, as well as a shared<br>library for use with other programs.<br>An integer overflow flaw was discovered in the bzip2 decompression routine.<br>This issue could, when decompressing malformed archives, cause bzip2, or an<br>application linked against the libbz2 library, to crash or, potentially,<br>execute arbitrary code. (CVE-2010-0405)<br>Users of bzip2 should upgrade to these updated packages, which contain a<br>backported patch to resolve this issue. All running applications using the<br>libbz2 library must be restarted for the update to take effect.<br>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/bzip2 | <1.0.3-6.el5_5 | 1.0.3-6.el5_5 |
redhat/bzip2 | <1.0.3-6.el5_5 | 1.0.3-6.el5_5 |
redhat/bzip2-devel | <1.0.3-6.el5_5 | 1.0.3-6.el5_5 |
redhat/bzip2-devel | <1.0.3-6.el5_5 | 1.0.3-6.el5_5 |
redhat/bzip2-libs | <1.0.3-6.el5_5 | 1.0.3-6.el5_5 |
redhat/bzip2-libs | <1.0.3-6.el5_5 | 1.0.3-6.el5_5 |
redhat/bzip2 | <1.0.2-16.el4_8 | 1.0.2-16.el4_8 |
redhat/bzip2 | <1.0.2-16.el4_8 | 1.0.2-16.el4_8 |
redhat/bzip2-devel | <1.0.2-16.el4_8 | 1.0.2-16.el4_8 |
redhat/bzip2-devel | <1.0.2-16.el4_8 | 1.0.2-16.el4_8 |
redhat/bzip2-libs | <1.0.2-16.el4_8 | 1.0.2-16.el4_8 |
redhat/bzip2-libs | <1.0.2-16.el4_8 | 1.0.2-16.el4_8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.