Bzip2

Vendor:

First CVE: Aug 12, 2002 · Active for 23 years

10
Total CVEs
More Total CVEs than 88% of tracked products
1.4
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
4.7
Avg CVSS
Higher Avg CVSS than 6% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Bzip2 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 12, 2002
23 years ago
Most Recent CVE
Jun 19, 2019
2,592 days ago

CVE Severity & Scoring

Bzip210 CVEs
All CVEs352,231 CVEs
LowMediumCritical
Attack Vector
Local0 (0.0%)
Network2 (20.0%)
Unknown8 (80.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (20.0%)
High0 (0.0%)
Unknown8 (80.0%)
User Interaction
None1 (10.0%)
Unknown8 (80.0%)
Required1 (10.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None2 (20.0%)
Unknown8 (80.0%)

Top CVEs

Signals from CVEs in this product scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.
Jun 19, 20199.834NONO
Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2 file, related to block ends set to befo
Jun 30, 20166.529NONO
The bzexe command in bzip2 1.0.5 and earlier generates compressed executables that do not properly handle temporary files during extraction, which allows local users to execute arb
Apr 16, 20144.628NOYES
Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 before 1.0.6 allows context-dependent attackers to cause a denial of service (application cras
Sep 28, 20105.121NONO
bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bzip2 file that causes an infinite loop (a.k.a "decompression bomb").
May 19, 20055.019NONO
bzlib.c in bzip2 before 1.0.5 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted file that triggers a buffer over-read, as demonstrated by the
Mar 18, 20084.315NONO
bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly other operating systems, does not use the O_EXCL flag to create files during decompression and
Aug 12, 20025.015NONO
Race condition in bzip2 1.0.2 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permiss
May 2, 20053.714NONO
bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly systems, uses the permissions of symbolic links instead of the actual files when creating an ar
Aug 12, 20022.111NONO
Race condition in bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly other operating systems, decompresses files with world-readable permissions b
Aug 12, 20021.210NONO

Exploit Exposure

Signals from CVEs in this product scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
10.0% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (10 CVEs).

Media Mentions

Signals from CVEs in this product scope (10 CVEs).

Top CNAs Publishing CVEs For Bzip2

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.0.616.515.8%00
1.0.415.13.3%00
1.0.334.72.9%01
1.0.244.42.3%01
1.0.173.71.6%01
1.073.71.6%01
0.9_c34.42.7%00
0.9_b34.42.7%00
0.9_a34.42.7%00
0.9.5_d24.41.8%00
0.9.5d53.52.0%00
0.9.5_c24.41.8%00
0.9.5c53.52.0%00
0.9.5_b24.41.8%00
0.9.5b53.52.0%00
0.9.5_a24.41.8%00
0.9.5a53.52.0%00
0.9.0c43.41.3%00
0.9.0b43.41.3%00
0.9.0a43.41.3%00