CVE-2009-1884

Severity CVSS v4.0:
Pending analysis
Type:
CWE-189 Numeric Errors
Publication date:
19/08/2009
Last modified:
09/04/2025

Description

Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attackers to cause a denial of service (application hang or crash) via a crafted bzip2 compressed stream that triggers a buffer overflow, a related issue to CVE-2009-1391.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bzip:compress-raw-bzip2:*:*:*:*:*:*:*:* 2.017 (including)
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.00_10:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.00_12:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.00_14:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.01:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.02:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.03:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.05:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.06:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.08:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.0.09:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.010:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.011:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.012:*:*:*:*:*:*:*
cpe:2.3:a:bzip:compress-raw-bzip2:2.014:*:*:*:*:*:*:*