CVE-2008-1372
bzlib.c in bzip2 before 1.0.5 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted file that triggers a buffer over-read, as demonstrated by the PROTOS GENOME test suite for Archive Formats.
- Bzip bzip2
- = 0.9, 0.9.5a, 0.9.5b, 0.9.5c, 0.9.5d, 0.9_a, 0.9_b, 0.9_c, 1.0, 1.0.1, 1.0.2, 1.0.3
- Fix
- Available
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 4.5% (91th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2008-03-18
CVE-2008-1372 at NVD
2 known exploits for CVE-2008-1372
Proof-of-concept code and exploit modules indexed by Sploitus