9.8

CVE-2019-12900

BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.

Data is provided by the National Vulnerability Database (NVD)
BzipBzip2 Version <= 1.0.6
DebianDebian Linux Version8.0
OpensuseLeap Version15.0
OpensuseLeap Version15.1
CanonicalUbuntu Linux Version12.04
CanonicalUbuntu Linux Version14.04 SwEditionesm
CanonicalUbuntu Linux Version16.04 SwEditionesm
CanonicalUbuntu Linux Version18.04 SwEditionlts
CanonicalUbuntu Linux Version19.04
FreebsdFreebsd Version11.2 Update-
FreebsdFreebsd Version11.2 Updatep10
FreebsdFreebsd Version11.2 Updatep11
FreebsdFreebsd Version11.2 Updatep12
FreebsdFreebsd Version11.2 Updatep2
FreebsdFreebsd Version11.2 Updatep3
FreebsdFreebsd Version11.2 Updatep4
FreebsdFreebsd Version11.2 Updatep5
FreebsdFreebsd Version11.2 Updatep6
FreebsdFreebsd Version11.2 Updatep7
FreebsdFreebsd Version11.2 Updatep8
FreebsdFreebsd Version11.2 Updatep9
FreebsdFreebsd Version11.2 Updaterc3
FreebsdFreebsd Version11.3 Update-
FreebsdFreebsd Version11.3 Updatep1
FreebsdFreebsd Version12.0 Update-
FreebsdFreebsd Version12.0 Updatep1
FreebsdFreebsd Version12.0 Updatep2
FreebsdFreebsd Version12.0 Updatep3
FreebsdFreebsd Version12.0 Updatep4
FreebsdFreebsd Version12.0 Updatep5
FreebsdFreebsd Version12.0 Updatep6
FreebsdFreebsd Version12.0 Updatep7
FreebsdFreebsd Version12.0 Updatep8
PythonPython Version >= 3.7.0 < 3.7.13
PythonPython Version >= 3.8.0 < 3.8.13
PythonPython Version >= 3.9.0 < 3.9.11
PythonPython Version >= 3.10.0 < 3.10.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.13% 0.776
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://seclists.org/bugtraq/2019/Aug/4
Patch
Third Party Advisory
Mailing List
https://seclists.org/bugtraq/2019/Jul/22
Third Party Advisory
Mailing List
https://usn.ubuntu.com/4038-1/
Third Party Advisory
https://usn.ubuntu.com/4038-2/
Third Party Advisory
https://usn.ubuntu.com/4146-1/
Third Party Advisory
https://usn.ubuntu.com/4146-2/
Third Party Advisory