RHSA-2024:10803: Low: bzip2 security update
Low: bzip2 security update
Other sources
The bzip2 packages contain a freely available, high-quality data compressor. It provides both standalone compression and decompression utilities, as well as a shared library for use with other programs. <br>Security Fix(es):<br><li> bzip2: out-of-bounds write in function BZ2decompress (CVE-2019-12900)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:10803?
The severity of RHSA-2024:10803 is classified as low.
How do I fix RHSA-2024:10803?
To fix RHSA-2024:10803, update the bzip2 package to version 1.0.8-8.el9_4.1.
Which systems are affected by RHSA-2024:10803?
RHSA-2024:10803 affects various Red Hat Enterprise Linux systems including those for Power LE, IBM z Systems, x86_64, and ARM 64.
What type of vulnerability is addressed in RHSA-2024:10803?
RHSA-2024:10803 addresses an out-of-bounds write vulnerability in the bzip2 packages.
Is there a specific version I need to update to for RHSA-2024:10803?
Yes, you need to update to version 1.0.8-8.el9_4.1 for the bzip2 package to mitigate the vulnerability.