Description
An issue was discovered in libbzip3.a in bzip3 1.2.2. There is a bz3_decompress out-of-bounds read in certain situations where buffers passed to bzip3 do not contain enough space to be filled with decompressed data. NOTE: the vendor's perspective is that the observed behavior can only occur for a contract violation, and thus the report is invalid.
Published: 2023-04-06
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

No history.

Subscriptions

Bzip3 Project Bzip3
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-02T14:07:46.221Z

Reserved: 2023-04-06T00:00:00.000Z

Link: CVE-2023-29417

cve-icon Vulnrichment

Updated: 2024-08-02T14:07:46.221Z

cve-icon NVD

Status : Modified

Published: 2023-04-06T05:15:07.500

Modified: 2024-11-21T07:57:01.327

Link: CVE-2023-29417

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses