5.1

CVE-2010-0405

Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 before 1.0.6 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted compressed file.

Data is provided by the National Vulnerability Database (NVD)
BzipBzip2 Version <= 1.0.5
BzipBzip2 Version0.9
BzipBzip2 Version0.9.0
BzipBzip2 Version0.9.0a
BzipBzip2 Version0.9.0b
BzipBzip2 Version0.9.0c
BzipBzip2 Version0.9.5_a
BzipBzip2 Version0.9.5_b
BzipBzip2 Version0.9.5_c
BzipBzip2 Version0.9.5_d
BzipBzip2 Version0.9.5a
BzipBzip2 Version0.9.5b
BzipBzip2 Version0.9.5c
BzipBzip2 Version0.9.5d
BzipBzip2 Version0.9_a
BzipBzip2 Version0.9_b
BzipBzip2 Version0.9_c
BzipBzip2 Version1.0
BzipBzip2 Version1.0.1
BzipBzip2 Version1.0.2
BzipBzip2 Version1.0.3
BzipBzip2 Version1.0.4
Libzip2Libzip2 Version <= 1.0.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 9.21% 0.919
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P