CVE-2009-1884: Buffer Overflow
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-1884 to the following vulnerability: Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attackers to cause a denial of service (application hang or crash) via a crafted bzip2 compressed stream that triggers a buffer overflow, a related issue to CVE-2009-1391. References: ----------- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1884 https://bugs.gentoo.org/show_bug.cgi?id=281955 https://bugs.gentoo.org/show_bug.cgi?id=281955
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1884?
CVE-2009-1884 has a severity rating that indicates it can lead to denial of service through application hangs or crashes.
How do I fix CVE-2009-1884?
To fix CVE-2009-1884, upgrade the Compress-Raw-Bzip2 module to version 2.018 or later.
Which versions are affected by CVE-2009-1884?
CVE-2009-1884 affects Compress-Raw-Bzip2 versions up to and including 2.017.
What is the nature of the vulnerability in CVE-2009-1884?
CVE-2009-1884 is an off-by-one error that can trigger a buffer overflow in the bzinflate function.
Who can exploit CVE-2009-1884?
Context-dependent attackers can exploit CVE-2009-1884 by crafting a specific bzip2 compressed stream.