Oval Definition:oval:org.mitre.oval:def:12643
Revision Date:2014-07-21Version:22
Title:DSA-2112-1 bzip2 -- integer overflow
Description:Mikolaj Izdebski has discovered an integer overflow flaw in the BZ2_decompress function in bzip2/libbz2. An attacker could use a crafted bz2 file to cause a denial of service or potentially to execute arbitrary code. After the upgrade, all running services that use libbz2 need to be restarted. This update also provides rebuilt dpkg packages, which are statically linked to the fixed version of libbz2. Updated packages for clamav, which is also affected by this issue, will be provided on debian-volatile. For the stable distribution, these problems have been fixed in version 1.0.4-1+lenny1. For the testing distribution and the unstable distribution, this problem in bzip2 will be fixed soon. Updated dpkg packages are not necessary for testing/unstable. We recommend that you upgrade your bzip2 / dpkg packages.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2010-0405
DSA-2112-1
Platform(s):Debian GNU/Linux 5.0
Product(s):bzip2
Definition Synopsis
  • Debian GNU/Linux 5.0 is installed
  • AND Architecture section
  • Architecture independet section
  • Installed architecture is all
  • AND zip2-doc DPKG is earlier than 1.0.5-1+lenny1
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is s390
  • OR Installed architecture is sparc
  • OR Installed architecture is i386
  • OR Installed architecture is powerpc
  • AND Packages section
  • lib64bz2-1.0 DPKG is earlier than 1.0.5-1+lenny1
  • OR libbz2-dev DPKG is earlier than 1.0.5-1+lenny1
  • OR lib64bz2-dev DPKG is earlier than 1.0.5-1+lenny1
  • OR zip2 DPKG is earlier than 1.0.5-1+lenny1
  • OR libbz2-1.0 DPKG is earlier than 1.0.5-1+lenny1
  • OR select DPKG is earlier than 1.14.29+b1
  • OR pkg DPKG is earlier than 1.14.29+b1
  • OR Architecture depended section
  • Installed architecture is amd64
  • AND Packages section
  • lib32bz2-1.0 DPKG is earlier than 1.0.5-1+lenny1
  • OR lib32bz2-dev DPKG is earlier than 1.0.5-1+lenny1
  • OR libbz2-dev DPKG is earlier than 1.0.5-1+lenny1
  • OR zip2 DPKG is earlier than 1.0.5-1+lenny1
  • OR libbz2-1.0 DPKG is earlier than 1.0.5-1+lenny1
  • OR select DPKG is earlier than 1.14.29+b1
  • OR pkg DPKG is earlier than 1.14.29+b1
  • OR Supported platform section
  • Installed architecture is hppa
  • AND Packages section
  • zip2 DPKG is earlier than 1.0.5-1+lenny1
  • OR libbz2-1.0 DPKG is earlier than 1.0.5-1+lenny1
  • OR pkg DPKG is earlier than 1.14.29+b1
  • OR select DPKG is earlier than 1.14.29+b1
  • OR libbz2-dev DPKG is earlier than 1.0.5-1+lenny1
  • BACK