USN-4038-1: bzip2 vulnerabilities
Published Jun 26, 2019
·Updated
Aladdin Mubaied discovered that bzip2 incorrectly handled certain files. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-3189) It was discovered that bzip2 incorrectly handled certain files. An attacker could possibly use this issue to execute arbitrary code. (CVE-2019-12900)
Affected Software
1 affected component
Bzip2 bzip2
Event History
May 10, 2025
Advisory Published
via Ubuntu·04:13 AM
Data Sourced
via Ubuntu·04:13 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-3189?
The severity of CVE-2016-3189 is moderate.
2
Is Ubuntu 19.04 affected by CVE-2016-3189?
Yes, Ubuntu 19.04 is affected by CVE-2016-3189.
3
How can I fix CVE-2016-3189 on Ubuntu 18.10?
To fix CVE-2016-3189 on Ubuntu 18.10, update the bzip2 and libbz2-1.0 packages to version 1.0.6-9ubuntu0.18.10 or later.
4
What versions of Ubuntu are affected by CVE-2019-12900?
Ubuntu 19.04, 18.10, 18.04, and 16.04 are affected by CVE-2019-12900.
5
Where can I find more information about these vulnerabilities?
More information about these vulnerabilities can be found on the Ubuntu website.