CVE-2009-1884

Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attackers to cause a denial of service (application hang or crash) via a crafted bzip2 compressed stream that triggers a buffer overflow, a related issue to CVE-2009-1391.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:bzip:compress-raw-bzip2:*:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.00_10:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.00_12:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.00_14:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.01:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.02:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.03:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.05:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.06:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.08:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.09:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.010:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.011:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.012:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.014:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.015:*:*:*:*:*:*:*
cpe:2.3:a:perl:perl:*:*:*:*:*:*:*:*

History

13 Feb 2023, 01:17

Type Values Removed Values Added
Summary CVE-2009-1884 perl-Compress-Raw-Bzip2: Off-by-one error in the bzinflate function - DoS (crash) Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attackers to cause a denial of service (application hang or crash) via a crafted bzip2 compressed stream that triggers a buffer overflow, a related issue to CVE-2009-1391.
References
  • {'url': 'https://access.redhat.com/security/cve/CVE-2009-1884', 'name': 'https://access.redhat.com/security/cve/CVE-2009-1884', 'tags': [], 'refsource': 'MISC'}

02 Feb 2023, 19:16

Type Values Removed Values Added
Summary Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attackers to cause a denial of service (application hang or crash) via a crafted bzip2 compressed stream that triggers a buffer overflow, a related issue to CVE-2009-1391. CVE-2009-1884 perl-Compress-Raw-Bzip2: Off-by-one error in the bzinflate function - DoS (crash)
References
  • (MISC) https://access.redhat.com/security/cve/CVE-2009-1884 -

Information

Published : 2009-08-19 17:30

Updated : 2023-12-10 10:51


NVD link : CVE-2009-1884

Mitre link : CVE-2009-1884

CVE.ORG link : CVE-2009-1884


JSON object : View

Products Affected

bzip

  • compress-raw-bzip2

perl

  • perl
CWE
CWE-189

Numeric Errors