Skip to main content

Vendor/product archive

bzip / bzip2 CVEs

Beta · best-effort

10 CVEs tagged to bzip / bzip21 Critical, 0 High, 6 Medium, 3 Low, 0 Unrated.

CVE-2016-3189

Published Jun 30, 2016

Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2 file, related to block ends set to bef…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4089

Published Apr 16, 2014

The bzexe command in bzip2 1.0.5 and earlier generates compressed executables that do not properly handle temporary files during extraction, which allows local users to execute ar…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0405

Published Sep 28, 2010

Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 before 1.0.6 allows context-dependent attackers to cause a denial of service (application cra…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1372

Published Mar 18, 2008

bzlib.c in bzip2 before 1.0.5 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted file that triggers a buffer over-read, as demonstrated by th…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0953

Published May 2, 2005

Race condition in bzip2 1.0.2 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permis…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2002-0759

Published Aug 12, 2002

bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly other operating systems, does not use the O_EXCL flag to create files during decompression and…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0760

Published Aug 12, 2002

Race condition in bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly other operating systems, decompresses files with world-readable permissions…

CVSS 1.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2002-0761

Published Aug 12, 2002

bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly systems, uses the permissions of symbolic links instead of the actual files when creating an a…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1