First published: Wed Jun 26 2019(Updated: )
Aladdin Mubaied discovered that bzip2 incorrectly handled certain files. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-3189) It was discovered that bzip2 incorrectly handled certain files. An attacker could possibly use this issue to execute arbitrary code. (CVE-2019-12900)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/bzip2 | <1.0.6-9ubuntu0.19.04 | 1.0.6-9ubuntu0.19.04 |
Ubuntu Ubuntu | =19.04 | |
All of | ||
ubuntu/libbz2-1.0 | <1.0.6-9ubuntu0.19.04 | 1.0.6-9ubuntu0.19.04 |
Ubuntu Ubuntu | =19.04 | |
All of | ||
ubuntu/bzip2 | <1.0.6-9ubuntu0.18.10 | 1.0.6-9ubuntu0.18.10 |
Ubuntu Ubuntu | =18.10 | |
All of | ||
ubuntu/libbz2-1.0 | <1.0.6-9ubuntu0.18.10 | 1.0.6-9ubuntu0.18.10 |
Ubuntu Ubuntu | =18.10 | |
All of | ||
ubuntu/bzip2 | <1.0.6-8.1ubuntu0.1 | 1.0.6-8.1ubuntu0.1 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/libbz2-1.0 | <1.0.6-8.1ubuntu0.1 | 1.0.6-8.1ubuntu0.1 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/bzip2 | <1.0.6-8ubuntu0.1 | 1.0.6-8ubuntu0.1 |
Ubuntu Ubuntu | =16.04 | |
All of | ||
ubuntu/libbz2-1.0 | <1.0.6-8ubuntu0.1 | 1.0.6-8ubuntu0.1 |
Ubuntu Ubuntu | =16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-3189 is moderate.
Yes, Ubuntu 19.04 is affected by CVE-2016-3189.
To fix CVE-2016-3189 on Ubuntu 18.10, update the bzip2 and libbz2-1.0 packages to version 1.0.6-9ubuntu0.18.10 or later.
Ubuntu 19.04, 18.10, 18.04, and 16.04 are affected by CVE-2019-12900.
More information about these vulnerabilities can be found on the Ubuntu website.