INFSA-2024:8922: bzip2 security update

Information about definition

Identificator: INFSA-2024:8922

Type: security

Release date: 2024-11-12 06:30:54 UTC

Information about package

The bzip2 packages contain a freely available, high-quality data compressor. It provides both standalone compression and decompression utilities, as well as a shared library for use with other programs.

Vulnerabilities description

  • CVE-2019-12900

    BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
no information 4 no information
Critical, important, moderate, low

Updated packages