oss-security September 2010 archive
Main Archive Page > Month Archives  > oss-security archives
oss-security: [oss-security] bzip2 CVE-2010-0405 integer overflo

[oss-security] bzip2 CVE-2010-0405 integer overflow

From: Solar Designer <solar_at_nospam>
Date: Tue Sep 21 2010 - 11:33:01 GMT
To: oss-security@lists.openwall.com

Hi,

Here's some analysis of this vulnerability and the changes in 1.0.6:

http://xorl.wordpress.com/2010/09/21/cve-2010-0405-bzip2-integer-overflow/

No conclusion on whether it is exploitable or not (and in what cases),
yet maybe this will save someone a few minutes.

Alexander