CVE-2008-1372

Publication date 18 March 2008

Last updated 24 July 2024


Ubuntu priority

bzlib.c in bzip2 before 1.0.5 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted file that triggers a buffer over-read, as demonstrated by the PROTOS GENOME test suite for Archive Formats.

Status

Package Ubuntu Release Status
bzip2 7.10 gutsy
Fixed 1.0.4-0ubuntu2.1
7.04 feisty
Fixed 1.0.3-6ubuntu0.1
6.10 edgy
Fixed 1.0.3-3ubuntu0.1
6.06 LTS dapper
Fixed 1.0.3-0ubuntu2.1

References

Related Ubuntu Security Notices (USN)

    • USN-590-1
    • bzip2 vulnerability
    • 24 March 2008

Other references