Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Date: Tue, 16 Sep 2008 16:13:48 -0500 Reply-To: Troy DawsonSender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for bzip2 on SL3.x, SL4.x, SL5.x i386/x86_64 Comments: To: " This email address is being protected from spambots. You need JavaScript enabled to view it. "Synopsis: Moderate: bzip2 security update Issue date: 2008-09-16 CVE Names: CVE-2008-1372 A buffer over-read flaw was discovered in the bzip2 decompression routine. This issue could cause an application linked against the libbz2 library to crash when decompressing malformed archives. (CVE-2008-1372) SL 3.0.x SRPMS: bzip2-1.0.2-12.EL3.src.rpm i386: bzip2-1.0.2-12.EL3.i386.rpm bzip2-devel-1.0.2-12.EL3.i386.rpm bzip2-libs-1.0.2-12.EL3.i386.rpm x86_64: bzip2-1.0.2-12.EL3.x86_64.rpm bzip2-devel-1.0.2-12.EL3.x86_64.rpm bzip2-libs-1.0.2-12.EL3.i386.rpm bzip2-libs-1.0.2-12.EL3.x86_64.rpm SL 4.x SRPMS: bzip2-1.0.2-14.el4_7.src.rpm i386: bzip2-1.0.2-14.el4_7.i386.rpm bzip2-devel-1.0.2-14.el4_7.i386.rpm bzip2-libs-1.0.2-14.el4_7.i386.rpm x86_64: bzip2-1.0.2-14.el4_7.x86_64.rpm bzip2-devel-1.0.2-14.el4_7.i386.rpm bzip2-devel-1.0.2-14.el4_7.x86_64.rpm bzip2-libs-1.0.2-14.el4_7.i386.rpm bzip2-libs-1.0.2-14.el4_7.x86_64.rpm SL 5.x SRPMS: bzip2-1.0.3-4.el5_2.src.rpm i386: bzip2-1.0.3-4.el5_2.i386.rpm bzip2-devel-1.0.3-4.el5_2.i386.rpm bzip2-libs-1.0.3-4.el5_2.i386.rpm x86_64: bzip2-1.0.3-4.el5_2.x86_64.rpm bzip2-devel-1.0.3-4.el5_2.i386.rpm bzip2-devel-1.0.3-4.el5_2.x86_64.rpm bzip2-libs-1.0.3-4.el5_2.i386.rpm bzip2-libs-1.0.3-4.el5_2.x86_64.rpm -Connie Sieh -Troy Dawson