An issue was discovered in libbzip3.a in bzip3 1.2.2. There is a bz3_decompress out-of-bounds read in certain situations where buffers passed to bzip3 do not contain enough space to be filled with decompressed data. NOTE: the vendor's perspective is that the observed behavior can only occur for a contract violation, and thus the report is invalid.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-04-06T00:00:00

Updated: 2024-08-02T14:07:46.221Z

Reserved: 2023-04-06T00:00:00

Link: CVE-2023-29417

cve-icon Vulnrichment

Updated: 2024-07-05T16:51:53.254Z

cve-icon NVD

Status : Modified

Published: 2023-04-06T05:15:07.500

Modified: 2024-11-21T07:57:01.327

Link: CVE-2023-29417

cve-icon Redhat

No data.