First published: Wed Nov 10 2010(Updated: )
bzip2 is a freely available, high-quality data compressor. It provides both<br>standalone compression and decompression utilities, as well as a shared<br>library for use with other programs.<br>An integer overflow flaw was discovered in the bzip2 decompression routine.<br>This issue could, when decompressing malformed archives, cause bzip2, or an<br>application linked against the libbz2 library, to crash or, potentially,<br>execute arbitrary code. (CVE-2010-0405)<br>Users of bzip2 should upgrade to these updated packages, which contain a<br>backported patch to resolve this issue. All running applications using the<br>libbz2 library must be restarted for the update to take effect.<br>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/bzip2 | <1.0.5-7.el6_0 | 1.0.5-7.el6_0 |
redhat/bzip2 | <1.0.5-7.el6_0 | 1.0.5-7.el6_0 |
redhat/bzip2-debuginfo | <1.0.5-7.el6_0 | 1.0.5-7.el6_0 |
redhat/bzip2-debuginfo | <1.0.5-7.el6_0 | 1.0.5-7.el6_0 |
redhat/bzip2-devel | <1.0.5-7.el6_0 | 1.0.5-7.el6_0 |
redhat/bzip2-devel | <1.0.5-7.el6_0 | 1.0.5-7.el6_0 |
redhat/bzip2-libs | <1.0.5-7.el6_0 | 1.0.5-7.el6_0 |
redhat/bzip2-libs | <1.0.5-7.el6_0 | 1.0.5-7.el6_0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2010:0858 is classified as important.
To resolve RHSA-2010:0858, update bzip2 and related packages to version 1.0.5-7.el6_0 or later.
The vulnerability in RHSA-2010:0858 is caused by an integer overflow flaw in the bzip2 decompression routine.
The affected packages in RHSA-2010:0858 include bzip2, bzip2-debuginfo, bzip2-devel, and bzip2-libs.
There is no official workaround for RHSA-2010:0858; updating to a secure version is recommended.