Computer Security
[EN] no-pyccku

unzip / bzip2 DoS
updated since 23.03.2008
SecurityVulns ID:8822
Threat Level:
Affected:BZIP : bzip2 1.0
 ANALOG : analog 6.0
CVE:CVE-2008-1372 (bzlib.c in bzip2 before 1.0.5 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted file that triggers a buffer over-read, as demonstrated by the PROTOS GENOME test suite for Archive Formats.)
 CVE-2008-0888 (The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data.)
Original documentdocumentGENTOO, [ GLSA 200903-40 ] Analog: Denial of Service (30.03.2009)
 documentRPATH, rPSA-2008-0118-1 bzip2 (23.03.2008)
 documentRPATH, rPSA-2008-0116-1 unzip (23.03.2008)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod