CVE-2019-12900
Published Jun 19, 2019
·Updated
BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.
Affected Software
41 affected componentsFixes available
Bzip bzip2<=1.0.6
Debian Debian Linux=8.0
openSUSE Leap=15.0
openSUSE Leap=15.1
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=19.04
FreeBSD FreeBSD=11.2
FreeBSD FreeBSD=11.2-p10
FreeBSD FreeBSD=11.2-p11
FreeBSD FreeBSD=11.2-p12
FreeBSD FreeBSD=11.2-p2
FreeBSD FreeBSD=11.2-p3
FreeBSD FreeBSD=11.2-p4
FreeBSD FreeBSD=11.2-p5
FreeBSD FreeBSD=11.2-p6
FreeBSD FreeBSD=11.2-p7
FreeBSD FreeBSD=11.2-p8
FreeBSD FreeBSD=11.2-p9
FreeBSD FreeBSD=11.2-rc3
FreeBSD FreeBSD=11.3
FreeBSD FreeBSD=11.3-p1
FreeBSD FreeBSD=12.0
FreeBSD FreeBSD=12.0-p1
FreeBSD FreeBSD=12.0-p2
FreeBSD FreeBSD=12.0-p3
FreeBSD FreeBSD=12.0-p4
FreeBSD FreeBSD=12.0-p5
FreeBSD FreeBSD=12.0-p6
FreeBSD FreeBSD=12.0-p7
FreeBSD FreeBSD=12.0-p8
Python Python>=3.7.0<3.7.13
Python Python>=3.8.0<3.8.13
Python Python>=3.9.0<3.9.11
Python Python>=3.10.0<3.10.3
debian/bzip2
1.0.8-41.0.8-51.0.8-6
debian/clamav
0.103.10+dfsg-0+deb11u11.0.7+dfsg-1~deb11u21.0.7+dfsg-1~deb12u11.4.3+dfsg-1
IBM DS8A00( R10.0 - R10.1 )<=10.1.3.0 - 10.10.106.0
IBM DS8900F ( R9.4)<=89.40.83.0-89.44.5.0
Remediation
Patch Available
Patch Available
Event History
Jun 19, 2019
CVE Published
via MITRE·10:07 PM
Data Sourced
via MITRE·10:07 PM
Description
Data Sourced
via NVD·11:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jun 27, 2019
Data Sourced
via Red Hat·07:16 AM
DescriptionSeverityAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·11:16 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·02:10 AM
RemedyDescriptionSeverityAffected Software
Dec 12, 2024
Updated
via Red Hat·02:02 PM
DescriptionSeverity
Jul 9, 2025
Data Sourced
via Debian·04:18 AM
DescriptionAffected Software
Dec 18, 2025
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2019-12900?
CVE-2019-12900 is a vulnerability in the BZ2_decompress function in bzip2 through version 1.0.6 that allows an out-of-bounds write when there are many selectors.
2
What is the severity of CVE-2019-12900?
The severity of CVE-2019-12900 is critical with a CVSS score of 9.8.
3
How does CVE-2019-12900 affect bzip2?
CVE-2019-12900 affects bzip2 versions 1.0.6 through 1.0.8 causing an out-of-bounds write in the BZ2_decompress function.
4
How can I fix CVE-2019-12900 in bzip2?
To fix CVE-2019-12900 in bzip2, update to version 1.0.9 or later.
5
Are there any references for CVE-2019-12900?
Yes, you can find references for CVE-2019-12900 at the following links: [1] GitLab commit: 74de1e2e6ffc9d51ef9824db71a8ffee5962cdbc [2] Debian LTS announce: June 2019 message [3] Ubuntu Security Notice: USN-4038-2.