5

CVE-2005-1260

bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bzip2 file that causes an infinite loop (a.k.a "decompression bomb").

Data is provided by the National Vulnerability Database (NVD)
BzipBzip2 Version < 1.0.3
CanonicalUbuntu Linux Version4.10
CanonicalUbuntu Linux Version5.04
DebianDebian Linux Version3.0
DebianDebian Linux Version3.1
ApplemacOS X Version < 10.4.11
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 9.8% 0.922
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.

http://www.securityfocus.com/bid/26444
Third Party Advisory
VDB Entry
http://www.us-cert.gov/cas/techalerts/TA07-319A.html
Third Party Advisory
US Government Resource
http://www.securityfocus.com/bid/13657
Third Party Advisory
VDB Entry
https://usn.ubuntu.com/127-1/
Third Party Advisory