Oval Definition:oval:com.redhat.rhsa:def:20080893
Revision Date:2008-09-16Version:635
Title:RHSA-2008:0893: bzip2 security update (Moderate)
Description:Bzip2 is a freely available, high-quality data compressor. It provides both stand-alone compression and decompression utilities, as well as a shared library for use with other programs.

  • A buffer over-read flaw was discovered in the bzip2 decompression routine. This issue could cause an application linked against the libbz2 library to crash when decompressing malformed archives. (CVE-2008-1372)

    Users of bzip2 should upgrade to these updated packages, which contain a backported patch to resolve this issue.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2008-1372
    RHSA-2008:0893
    RHSA-2008:0893-01
    RHSA-2008:0893-01
    Platform(s):Red Hat Enterprise Linux 3
    Red Hat Enterprise Linux 4
    Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • bzip2-libs is earlier than 0:1.0.2-12.EL3
  • AND bzip2-libs is signed with Red Hat master key
  • bzip2-devel is earlier than 0:1.0.2-12.EL3
  • AND bzip2-devel is signed with Red Hat master key
  • bzip2 is earlier than 0:1.0.2-12.EL3
  • AND bzip2 is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • bzip2-libs is earlier than 0:1.0.2-14.el4_7
  • AND bzip2-libs is signed with Red Hat master key
  • bzip2 is earlier than 0:1.0.2-14.el4_7
  • AND bzip2 is signed with Red Hat master key
  • bzip2-devel is earlier than 0:1.0.2-14.el4_7
  • AND bzip2-devel is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • bzip2-libs is earlier than 0:1.0.3-4.el5_2
  • AND bzip2-libs is signed with Red Hat redhatrelease key
  • bzip2 is earlier than 0:1.0.3-4.el5_2
  • AND bzip2 is signed with Red Hat redhatrelease key
  • bzip2-devel is earlier than 0:1.0.3-4.el5_2
  • AND bzip2-devel is signed with Red Hat redhatrelease key
  • Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • bzip2 is earlier than 0:1.0.2-14.el4_7
  • AND bzip2 is signed with Red Hat redhatrelease2 key
  • bzip2-devel is earlier than 0:1.0.2-14.el4_7
  • AND bzip2-devel is signed with Red Hat redhatrelease2 key
  • bzip2-libs is earlier than 0:1.0.2-14.el4_7
  • AND bzip2-libs is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • bzip2 is earlier than 0:1.0.3-4.el5_2
  • AND bzip2 is signed with Red Hat redhatrelease2 key
  • bzip2-devel is earlier than 0:1.0.3-4.el5_2
  • AND bzip2-devel is signed with Red Hat redhatrelease2 key
  • bzip2-libs is earlier than 0:1.0.3-4.el5_2
  • AND bzip2-libs is signed with Red Hat redhatrelease2 key
  • Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • bzip2 is earlier than 0:1.0.2-12.EL3
  • AND bzip2 is signed with Red Hat master key
  • bzip2-devel is earlier than 0:1.0.2-12.EL3
  • AND bzip2-devel is signed with Red Hat master key
  • bzip2-libs is earlier than 0:1.0.2-12.EL3
  • AND bzip2-libs is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • bzip2 is earlier than 0:1.0.2-14.el4_7
  • AND bzip2 is signed with Red Hat master key
  • bzip2-devel is earlier than 0:1.0.2-14.el4_7
  • AND bzip2-devel is signed with Red Hat master key
  • bzip2-libs is earlier than 0:1.0.2-14.el4_7
  • AND bzip2-libs is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • bzip2 is earlier than 0:1.0.3-4.el5_2
  • AND bzip2 is signed with Red Hat redhatrelease key
  • bzip2-devel is earlier than 0:1.0.3-4.el5_2
  • AND bzip2-devel is signed with Red Hat redhatrelease key
  • bzip2-libs is earlier than 0:1.0.3-4.el5_2
  • AND bzip2-libs is signed with Red Hat redhatrelease key
  • BACK