CVE-2009-1884

Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attackers to cause a denial of service (application hang or crash) via a crafted bzip2 compressed stream that triggers a buffer overflow, a related issue to CVE-2009-1391.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:bzip:compress-raw-bzip2:*:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.00_10:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.00_12:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.00_14:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.01:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.02:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.03:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.05:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.06:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.08:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.09:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.010:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.011:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.012:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.014:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.015:*:*:*:*:*:*:*
cpe:2.3:a:perl:perl:*:*:*:*:*:*:*:*

History

21 Nov 2024, 01:03

Type Values Removed Values Added
References () http://secunia.com/advisories/36386 - Vendor Advisory () http://secunia.com/advisories/36386 - Vendor Advisory
References () http://secunia.com/advisories/36415 - () http://secunia.com/advisories/36415 -
References () http://security.gentoo.org/glsa/glsa-200908-07.xml - () http://security.gentoo.org/glsa/glsa-200908-07.xml -
References () http://www.securityfocus.com/bid/36082 - Patch () http://www.securityfocus.com/bid/36082 - Patch
References () https://bugs.gentoo.org/show_bug.cgi?id=281955 - () https://bugs.gentoo.org/show_bug.cgi?id=281955 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=518278 - () https://bugzilla.redhat.com/show_bug.cgi?id=518278 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/52628 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/52628 -
References () https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00982.html - () https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00982.html -
References () https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00999.html - () https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00999.html -

Information

Published : 2009-08-19 17:30

Updated : 2024-11-21 01:03


NVD link : CVE-2009-1884

Mitre link : CVE-2009-1884

CVE.ORG link : CVE-2009-1884


JSON object : View

Products Affected

bzip

  • compress-raw-bzip2

perl

  • perl
CWE
CWE-189

Numeric Errors