CVE-2008-1372: Buffer Overflow
Published Mar 18, 2008
·Updated
bzlib.c in bzip2 before 1.0.5 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted file that triggers a buffer over-read, as demonstrated by the PROTOS GENOME test suite for Archive Formats.
Affected Software
12 affected components
Bzip bzip2=1.0
Bzip bzip2=0.9_a
Bzip bzip2=0.9.5d
Bzip bzip2=0.9_c
Bzip bzip2=1.0.3
Bzip bzip2=1.0.2
Bzip bzip2=0.9.5a
Bzip bzip2=0.9.5b
Bzip bzip2=0.9
Bzip bzip2=1.0.1
Bzip bzip2=0.9.5c
Bzip bzip2=0.9_b
Event History
Mar 18, 2008
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-1372?
CVE-2008-1372 is classified as a denial of service vulnerability.
2
How do I fix CVE-2008-1372?
To fix CVE-2008-1372, upgrade to bzip2 version 1.0.5 or later.
3
What types of attacks does CVE-2008-1372 enable?
CVE-2008-1372 allows remote attackers to cause denial of service by triggering a buffer over-read.
4
Which versions of bzip2 are affected by CVE-2008-1372?
Affected versions of bzip2 include 0.9, 0.9.5a, 0.9.5b, 0.9.5c, 0.9.5d, and all 1.0.x versions prior to 1.0.5.
5
What is the impact of exploiting CVE-2008-1372?
Exploiting CVE-2008-1372 can lead to application crashes and service downtime.