Lucene search

K
cve[email protected]CVE-2010-0405
HistorySep 28, 2010 - 6:00 p.m.

CVE-2010-0405

2010-09-2818:00:02
CWE-189
web.nvd.nist.gov
69
cve-2010-0405
integer overflow
bz2_decompress
bzip2
libbzip2
dos
denial of service
arbitrary code execution
nvd

5.1 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

6.6 Medium

AI Score

Confidence

High

0.027 Low

EPSS

Percentile

90.6%

Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 before 1.0.6 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted compressed file.

Affected configurations

NVD
Node
bzipbzip2Range1.0.5
OR
bzipbzip2Match0.9
OR
bzipbzip2Match0.9.0
OR
bzipbzip2Match0.9.0a
OR
bzipbzip2Match0.9.0b
OR
bzipbzip2Match0.9.0c
OR
bzipbzip2Match0.9.5_a
OR
bzipbzip2Match0.9.5_b
OR
bzipbzip2Match0.9.5_c
OR
bzipbzip2Match0.9.5_d
OR
bzipbzip2Match0.9.5a
OR
bzipbzip2Match0.9.5b
OR
bzipbzip2Match0.9.5c
OR
bzipbzip2Match0.9.5d
OR
bzipbzip2Match0.9_a
OR
bzipbzip2Match0.9_b
OR
bzipbzip2Match0.9_c
OR
bzipbzip2Match1.0
OR
bzipbzip2Match1.0.1
OR
bzipbzip2Match1.0.2
OR
bzipbzip2Match1.0.3
OR
bzipbzip2Match1.0.4
OR
libzip2libzip2Range1.0.5

References

5.1 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

6.6 Medium

AI Score

Confidence

High

0.027 Low

EPSS

Percentile

90.6%