Oval Definition:oval:org.mitre.oval:def:29039
Revision Date:2015-08-17Version:9
Title:RHSA-2008:0893 -- bzip2 security update (Moderate)
Description:Updated bzip2 packages that fix a security issue are now available for RedHat Enterprise Linux 2.1, 3, 4, and 5.This update has been rated as having moderate security impact by the RedHat Security Response Team.Bzip2 is a freely available, high-quality data compressor. It provides bothstand-alone compression and decompression utilities, as well as a sharedlibrary for use with other programs.A buffer over-read flaw was discovered in the bzip2 decompression routine.This issue could cause an application linked against the libbz2 library tocrash when decompressing malformed archives. (CVE-2008-1372)Users of bzip2 should upgrade to these updated packages, which contain abackported patch to resolve this issue.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CESA-2008:0893-CentOS 2
CESA-2008:0893-CentOS 3
CESA-2008:0893-CentOS 5
CVE-2008-1372
RHSA-2008:0893
Platform(s):CentOS Linux 2
CentOS Linux 3
CentOS Linux 5
Red Hat Enterprise Linux 3
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Product(s):bzip2
Definition Synopsis
  • Red Hat Enterprise Linux 5 and CentOS Linux 5 release section
  • Operation system section
  • The operating system installed on the system is Red Hat Enterprise Linux 5
  • OR The operating system installed on the system is CentOS Linux 5.x
  • AND Packages match section
  • bzip2-devel is earlier than 0:1.0.3-4.el5_2
  • OR bzip2 is earlier than 0:1.0.3-4.el5_2
  • OR bzip2-libs is earlier than 0:1.0.3-4.el5_2
  • Red Hat Enterprise Linux 3 release section
  • The operating system installed on the system is Red Hat Enterprise Linux 3
  • AND Packages match section
  • bzip2 is earlier than 0:1.0.2-12.EL3
  • OR bzip2-devel is earlier than 0:1.0.2-12.EL3
  • OR bzip2-libs is earlier than 0:1.0.2-12.EL3
  • Red Hat Enterprise Linux 4 release section
  • The operating system installed on the system is Red Hat Enterprise Linux 4
  • AND Packages match section
  • bzip2 is earlier than 0:1.0.2-14.el4_7
  • OR bzip2-devel is earlier than 0:1.0.2-14.el4_7
  • OR bzip2-libs is earlier than 0:1.0.2-14.el4_7
  • BACK