bzip2
cpe:2.3:a:bzip2_project:bzip2:*:*:*:*:rust:*:*
- < 1.0.9
A vulnerability exists in bzip2 versions prior to 1.0.9, specifically within the bzip2recover utility. The issue arises from an off-by-one error that allows for an out-of-bounds write to a global buffer when the application processes specially crafted files. This memory corruption causes a crash, creating a denial-of-service condition.
Exploitation of this vulnerability results in memory corruption, causing the application to crash and leading to a denial-of-service condition.
Users can upgrade to bzip2 version 1.0.9 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.