CVE-2009-1884

Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attackers to cause a denial of service (application hang or crash) via a crafted bzip2 compressed stream that triggers a buffer overflow, a related issue to CVE-2009-1391.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:bzip:compress-raw-bzip2:*:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.00_10:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.00_12:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.00_14:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.01:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.02:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.03:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.05:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.06:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.08:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.09:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.010:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.011:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.012:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.014:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.015:*:*:*:*:*:*:*
cpe:2.3:a:perl:perl:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2009-08-19 17:30

Updated : 2024-02-04 17:33


NVD link : CVE-2009-1884

Mitre link : CVE-2009-1884

CVE.ORG link : CVE-2009-1884


JSON object : View

Products Affected

perl

  • perl

bzip

  • compress-raw-bzip2
CWE
CWE-189

Numeric Errors