Friday, September 24, 2010

bzip2: integer overflow

Users of bzip2 please be advised of an integer overflow vulnerability that has been identified.

To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx)

Amplify’d from www.criticalwatch.com
MDVSA-2010:185: [MDVSA-2010:185] bzip2 integer overflow
Problem Description:



An integer overflow has been found and corrected in bzip2 which could

be exploited by using a specially crafted bz2 file and cause a denial

of service attack (CVE-2010-0405).


Read more at www.criticalwatch.com
 

No comments:

Post a Comment