Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora: 2009-8868 Moderate: perl-Compress-Raw-Bzip2 DoS Threat

fedora
Calendar Grey August 21, 2009
Dist Fedora Esm H88
Fedora's update for perl-Compress-Raw-Bzip2 addresses a crucial buffer overflow vulnerability, enhancing performance and security for users to apply promptly
Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw- Bzip2 module before 2.018 for Perl allows context-dependent attackers to cause a denial of service (a...

Summary

This module provides a Perl interface to the bzip2 compression library.

It is used by IO::Compress::Bzip2.

Update Information:

Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw- Bzip2 module before 2.018 for Perl allows context-dependent attackers to cause a denial of service (application hang or crash) via a crafted bzip2 compressed stream that triggers a buffer overflow, a related issue to CVE-2009-1391.

Change Log

* Thu Aug 20 2009 Marcela Mašláňová - 2.020-1 - 518278 CVE-2009-1884, update to the latest release

References


[ 1 ] Bug #518278 - CVE-2009-1884 perl-Compress-Raw-Bzip2: Off-by-one error in the bzinflate function - DoS (crash) https://bugzilla.redhat.com/show_bug.cgi?id=518278

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update perl-Compress-Raw-Bzip2' at the command line. For more information, refer to "Managing Software with yum", available at .

Name: perl-Compress-Raw-Bzip2
Product: Fedora 11
Version: 2.020
Release: 1.fc11
Summary: Low-Level Interface to bzip2 compression library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here