Bzip is a data compression utility whose bzip2 implementation is embedded across numerous software projects and systems, making it a foundational component in the software supply chain despite its narrowly focused product scope. Vulnerabilities in this compression library recur through memory-safety weakness classes including out-of-bounds writes, use-after-free conditions, and uncontrolled resource consumption, exposures that are characteristic of native-code parsers and reflect the parsing complexity inherent to decompression algorithms. Defenders should inventory applications and systems bundling bzip2 rather than tracking the library in isolation, since remediation typically cascades through downstream vendors; current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bzip over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12900CRITICAL BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors. | Jun 19, 2019 | 9.8 | 34 | NO | NO |
CVE-2016-3189MEDIUM Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2 file, related to block ends set to befo | Jun 30, 2016 | 6.5 | 29 | NO | NO |
CVE-2011-4089MEDIUM The bzexe command in bzip2 1.0.5 and earlier generates compressed executables that do not properly handle temporary files during extraction, which allows local users to execute arb | Apr 16, 2014 | 4.6 | 28 | NO | YES |
CVE-2010-0405MEDIUM Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 before 1.0.6 allows context-dependent attackers to cause a denial of service (application cras | Sep 28, 2010 | 5.1 | 21 | NO | NO |
CVE-2005-1260MEDIUM bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bzip2 file that causes an infinite loop (a.k.a "decompression bomb"). | May 19, 2005 | 5.0 | 19 | NO | NO |
CVE-2009-1884MEDIUM Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attackers to cause a denial of service (appli | Aug 19, 2009 | 4.3 | 17 | NO | NO |
CVE-2008-1372MEDIUM bzlib.c in bzip2 before 1.0.5 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted file that triggers a buffer over-read, as demonstrated by the | Mar 18, 2008 | 4.3 | 15 | NO | NO |
CVE-2002-0759MEDIUM bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly other operating systems, does not use the O_EXCL flag to create files during decompression and | Aug 12, 2002 | 5.0 | 15 | NO | NO |
Race condition in bzip2 1.0.2 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permiss | May 2, 2005 | 3.7 | 14 | NO | NO |
bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly systems, uses the permissions of symbolic links instead of the actual files when creating an ar | Aug 12, 2002 | 2.1 | 11 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bzip.
Media articles that mention a CVE ID that affects a product developed by Bzip — matched by CVE ID, not by vendor name.