Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 904037 (CVE-2023-29415, CVE-2023-29416, CVE-2023-29418, CVE-2023-29419, CVE-2023-29420, CVE-2023-29421) - <app-arch/bzip3-1.3.0: multiple vulnerabilities
Summary: <app-arch/bzip3-1.3.0: multiple vulnerabilities
Status: CONFIRMED
Alias: CVE-2023-29415, CVE-2023-29416, CVE-2023-29418, CVE-2023-29419, CVE-2023-29420, CVE-2023-29421
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor
Assignee: Gentoo Security
URL:
Whiteboard: B3 [glsa?]
Keywords:
Depends on: 904040
Blocks:
  Show dependency tree
 
Reported: 2023-04-08 16:38 UTC by John Helmert III
Modified: 2023-04-30 23:00 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-04-08 16:38:03 UTC
CVE-2023-29415 (https://github.com/kspalaiologos/bzip3/issues/95):

An issue was discovered in libbzip3.a in bzip3 before 1.3.0. A denial of service (process hang) can occur with a crafted archive because bzip3 does not follow the required procedure for interacting with libsais.

CVE-2023-29416 (https://github.com/kspalaiologos/bzip3/issues/92):

An issue was discovered in libbzip3.a in bzip3 before 1.3.0. A bz3_decode_block out-of-bounds write can occur with a crafted archive because bzip3 does not follow the required procedure for interacting with libsais.

CVE-2023-29418 (https://github.com/kspalaiologos/bzip3/issues/92):

An issue was discovered in libbzip3.a in bzip3 before 1.2.3. There is an xwrite out-of-bounds read.

CVE-2023-29419 (https://github.com/kspalaiologos/bzip3/issues/92):

An issue was discovered in libbzip3.a in bzip3 before 1.2.3. There is a bz3_decode_block out-of-bounds read.

CVE-2023-29420 (https://github.com/kspalaiologos/bzip3/issues/92):

An issue was discovered in libbzip3.a in bzip3 before 1.2.3. There is a crash caused by an invalid memmove in bz3_decode_block.

CVE-2023-29421 (https://github.com/kspalaiologos/bzip3/issues/94):

An issue was discovered in libbzip3.a in bzip3 before 1.2.3. There is an out-of-bounds write in bz3_decode_block.

Seems like all issues are indeed fixed in 1.3.0. Please stabilize.

ago: please request update(s) to the CVE(s) per
https://github.com/kspalaiologos/bzip3/issues/95#issuecomment-1500039775