Resource Exhaustion Affecting bzip2 package, versions <1.0.2-7


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
17.96% (97th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Resource Exhaustion vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-DEBIAN13-BZIP2-5676111
  • published19 May 2005
  • disclosed19 May 2005

Introduced: 19 May 2005

CVE-2005-1260  (opens in a new tab)
CWE-400  (opens in a new tab)

How to fix?

Upgrade Debian:13 bzip2 to version 1.0.2-7 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream bzip2 package and not the bzip2 package as distributed by Debian. See How to fix? for Debian:13 relevant fixed versions and status.

bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bzip2 file that causes an infinite loop (a.k.a "decompression bomb").

CVSS Scores

version 3.1