CVE-2023-29415

An issue was discovered in libbzip3.a in bzip3 before 1.3.0. A denial of service (process hang) can occur with a crafted archive because bzip3 does not follow the required procedure for interacting with libsais.
Configurations

Configuration 1 (hide)

cpe:2.3:a:bzip3_project:bzip3:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*

History

07 Nov 2023, 04:11

Type Values Removed Values Added
References
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NA7S7HDUAINOTCSWQZ5LIW756DYY22V2/', 'name': 'FEDORA-2023-3a821e6e73', 'tags': [], 'refsource': 'FEDORA'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NMLFV2FJK3CM7NJLVPZI5RUAFQZICPWW/', 'name': 'FEDORA-2023-3589ad1c55', 'tags': [], 'refsource': 'FEDORA'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4JLSE25SV7K2NB6FTFT4UHJOJUHBHYHY/', 'name': 'FEDORA-2023-c08f9dfc16', 'tags': [], 'refsource': 'FEDORA'}
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4JLSE25SV7K2NB6FTFT4UHJOJUHBHYHY/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NA7S7HDUAINOTCSWQZ5LIW756DYY22V2/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NMLFV2FJK3CM7NJLVPZI5RUAFQZICPWW/ -

15 Apr 2023, 04:16

Type Values Removed Values Added
References
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NMLFV2FJK3CM7NJLVPZI5RUAFQZICPWW/ -

14 Apr 2023, 03:15

Type Values Removed Values Added
References
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NA7S7HDUAINOTCSWQZ5LIW756DYY22V2/ -
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4JLSE25SV7K2NB6FTFT4UHJOJUHBHYHY/ -

12 Apr 2023, 17:25

Type Values Removed Values Added
References (MISC) https://github.com/kspalaiologos/bzip3/issues/95 - (MISC) https://github.com/kspalaiologos/bzip3/issues/95 - Exploit, Issue Tracking, Patch, Third Party Advisory
References (MISC) https://github.com/kspalaiologos/bzip3/compare/1.2.3...1.3.0 - (MISC) https://github.com/kspalaiologos/bzip3/compare/1.2.3...1.3.0 - Patch
References (MISC) https://security-tracker.debian.org/tracker/CVE-2023-29415 - (MISC) https://security-tracker.debian.org/tracker/CVE-2023-29415 - Third Party Advisory
CPE cpe:2.3:a:bzip3_project:bzip3:*:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE NVD-CWE-noinfo
First Time Bzip3 Project
Bzip3 Project bzip3
Debian debian Linux
Debian

07 Apr 2023, 14:15

Type Values Removed Values Added
References
  • (MISC) https://security-tracker.debian.org/tracker/CVE-2023-29415 -

06 Apr 2023, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-04-06 05:15

Updated : 2023-12-10 15:01


NVD link : CVE-2023-29415

Mitre link : CVE-2023-29415

CVE.ORG link : CVE-2023-29415


JSON object : View

Products Affected

bzip3_project

  • bzip3

debian

  • debian_linux