CVE-2023-29421
Summary
| CVE | CVE-2023-29421 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-04-06 05:15:00 UTC |
| Updated | 2023-11-07 04:11:00 UTC |
| Description | An issue was discovered in libbzip3.a in bzip3 before 1.2.3. There is an out-of-bounds write in bz3_decode_block. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Bzip3 Project |
Bzip3 |
All |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| Comparing 1.2.2...1.2.3 · kspalaiologos/bzip3 · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 36 Update: bzip3-1.3.0-1.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 38 Update: bzip3-1.3.0-1.fc38 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: bzip3-1.3.0-1.fc36 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 38 Update: bzip3-1.3.0-1.fc38 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 37 Update: bzip3-1.3.0-1.fc37 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| heap-based buffer overflow WRITE in bz3_decode_block() · Issue #94 · kspalaiologos/bzip3 · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 37 Update: bzip3-1.3.0-1.fc37 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 182546 Debian Security Update for bzip3 (CVE-2023-29421)
- 283885 Fedora Security Update for bzip3 (FEDORA-2023-3a821e6e73)
- 283886 Fedora Security Update for bzip3 (FEDORA-2023-c08f9dfc16)
- 284197 Fedora Security Update for bzip3 (FEDORA-2023-3589ad1c55)