bzip2: crash on malformed archive file
Published Mar 18, 2008
4.3
MEDIUMCVSS 2.0
EPSS 4.52%
Description
bzlib.c in bzip2 before 1.0.5 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted file that triggers a buffer over-read, as demonstrated by the PROTOS GENOME test suite for Archive Formats.
Affected products
No data.
- 0.9
- 0.9.5a
- 0.9.5b
- 0.9.5c
- 0.9.5d
- 0.9_a
- 0.9_b
- 0.9_c
- 1.0
- 1.0.1
- 1.0.2
- 1.0.3
No data.
Red Hat Enterprise Linux 2.1
bzip2-0:1.0.1-5.EL2.1
Fixed · RHSA-2008:0893
Red Hat Enterprise Linux 3
bzip2-0:1.0.2-12.EL3
Fixed · RHSA-2008:0893
Red Hat Enterprise Linux 4
bzip2-0:1.0.2-14.el4_7
Fixed · RHSA-2008:0893
Red Hat Enterprise Linux 5
bzip2-0:1.0.3-4.el5_2
Fixed · RHSA-2008:0893
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 2.1 | bzip2-0:1.0.1-5.EL2.1 | Fixed | RHSA-2008:0893 |
| Red Hat Enterprise Linux 3 | bzip2-0:1.0.2-12.EL3 | Fixed | RHSA-2008:0893 |
| Red Hat Enterprise Linux 4 | bzip2-0:1.0.2-14.el4_7 | Fixed | RHSA-2008:0893 |
| Red Hat Enterprise Linux 5 | bzip2-0:1.0.3-4.el5_2 | Fixed | RHSA-2008:0893 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (16 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 4.52% (0.04519) | 91.23th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.52% (0.04519) | 90.28th | v5 (v2026.06.15) |
| Nov 17, 2025 | 7.74% (0.07739) | 91.56th | v4 (v2025.03.14) |
| Oct 7, 2025 | 8.87% (0.08874) | 92.21th | v4 (v2025.03.14) |
| May 3, 2025 | 6.90% (0.06896) | 90.91th | v4 (v2025.03.14) |
| Mar 30, 2025 | 20.44% (0.20440) | 95.07th | v4 (v2025.03.14) |
| Mar 29, 2025 | 41.99% (0.41993) | 96.16th | v4 (v2025.03.14) |
| Mar 17, 2025 | 20.44% (0.20440) | 95.08th | v4 (v2025.03.14) |
| Feb 27, 2025 | 7.01% (0.07013) | 94.02th | v3 (v2023.03.01) |
| Dec 13, 2024 | 10.95% (0.10945) | 95.37th | v3 (v2023.03.01) |
| Aug 20, 2024 | 8.61% (0.08606) | 94.60th | v3 (v2023.03.01) |
| Jun 7, 2024 | 9.66% (0.09664) | 94.80th | v3 (v2023.03.01) |
| Mar 7, 2023 | 8.61% (0.08606) | 93.43th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.93% (0.03932) | 85.88th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.93% (0.03932) | 84.43th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.93% (0.03932) | 67.70th | v2 (v2022.01.01) |
References (50)
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-004.txt.asc vendor-advisoryx_refsource_NETBSD
- http://kb.vmware.com/kb/1006982 x_refsource_CONFIRM
- http://kb.vmware.com/kb/1007198 x_refsource_CONFIRM
- http://kb.vmware.com/kb/1007504 x_refsource_CONFIRM
- http://lists.apple.com/archives/security-announce/2009/Aug/msg00001.html vendor-advisoryx_refsource_APPLE
- http://lists.opensuse.org/opensuse-security-announce/2008-05/msg00000.html vendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/29410 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29475 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29497 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29506 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29656 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29677 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29698 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29940 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/31204 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/31869 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/31878 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/36096 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-200903-40.xml vendor-advisoryx_refsource_GENTOO
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-241786-1 vendor-advisoryx_refsource_SUNALERT
- http://support.apple.com/kb/HT3757 x_refsource_CONFIRM
- http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0118 x_refsource_CONFIRM
- http://www.bzip.org/CHANGES x_refsource_CONFIRM
- http://www.cert.fi/haavoittuvuudet/joint-advisory-archive-formats.html x_refsource_MISC
- http://www.ee.oulu.fi/research/ouspg/protos/testing/c10/archive/ x_refsource_MISC
- http://www.gentoo.org/security/en/glsa/glsa-200804-02.xml vendor-advisoryx_refsource_GENTOO
- http://www.ipcop.org/index.php?name=News&file=article&sid=40 x_refsource_CONFIRM
- http://www.kb.cert.org/vuls/id/813451 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:075 vendor-advisoryx_refsource_MANDRIVA
- http://www.redhat.com/support/errata/RHSA-2008-0893.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/489968/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/498863/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/28286 vdb-entryx_refsource_BIDExploit
- http://www.securitytracker.com/id?1020867 vdb-entryx_refsource_SECTRACK
- http://www.slackware.org/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.473263 vendor-advisoryx_refsource_SLACKWARE
- http://www.us-cert.gov/cas/techalerts/TA09-218A.html third-party-advisoryx_refsource_CERTUS Government Resource
- http://www.vupen.com/english/advisories/2008/0915 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2008/2557 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2009/2172 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2008-1372 Vendor Advisory
- https://bugs.gentoo.org/attachment.cgi?id=146488&action=view x_refsource_CONFIRM
- https://bugzilla.redhat.com/show_bug.cgi?id=438118 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41249 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2008-1372
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10067 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6467 vdb-entrysignaturex_refsource_OVAL
- https://usn.ubuntu.com/590-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2008-1372
- https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00165.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00225.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.