CVE-2019-12900 describes an out-of-bounds write vulnerability in the BZ2_decompress function of bzip2 versions through 1.0.6, impacting various distributions including Debian, FreeBSD, and OpenSUSE, as well as Python. This critical vulnerability, with a CVSS score of 9.8, allows unauthenticated attackers to achieve high confidentiality, integrity, and availability impacts over a network with low attack complexity. Despite its severity and high FAUCET Risk Score, there is no evidence of active exploitation, nor are there publicly available exploits in Metasploit or ExploitDB. Community discussion and media coverage are minimal, with only one mention and one article referencing it, primarily in the context of Juniper Networks patching unrelated vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0.6CPE matchmatch criteria | cpe:2.3:a:bzip:bzip2:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* | ||
12.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
bzip2: bzip2: Data integrity error when decompressing (with data integrity tests fail).
Nov 15, 2024CVE-2019-12900
Aug 11, 2020BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.
Jun 11, 2019