bzip2 is vulnerable to Out-of-bounds Write
48
Medium Risk
Affected versions of bzip2 have an off-by-one error in the bzip2recover utility's block-boundary scanner. A crafted file with more than 50,000 copies of the 48-bit bzip2 block-header magic writes one element past the global bStart/bEnd buffers, corrupting memory and crashing the process.
You are affected if you are using a version that falls within the vulnerable range and you run the bzip2recover utility on untrusted or damaged .bz2 files.
bzip2 is vulnerable to Out-of-bounds Write in versions 0.0.1 - 1.0.8.
There is no patched release yet. Upgrade bzip2 once a version newer than 1.0.8 is published, or apply this patch. Until then, do not run bzip2recover on untrusted files.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.