Sploitus

CVE-2008-1372

2 known exploits for CVE-2008-1372

bzlib.c in bzip2 before 1.0.5 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted file that triggers a buffer over-read, as demonstrated by the PROTOS GENOME test suite for Archive Formats.

Affected products
Red Hat, Bzip2
Bzip bzip2
= 0.9, 0.9.5a, 0.9.5b, 0.9.5c, 0.9.5d, 0.9_a, 0.9_b, 0.9_c, 1.0, 1.0.1, 1.0.2, 1.0.3
Fix
Available
CVSS 2.0
4.3 MEDIUM
EPSS
4.5% (91th percentile)
Weakness
CWE-119
NVD status
Modified
Published
2008-03-18
CVE-2008-1372 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2008-1372

Proof-of-concept code and exploit modules indexed by Sploitus