CVE-2009-1884

NameCVE-2009-1884
DescriptionOff-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attackers to cause a denial of service (application hang or crash) via a crafted bzip2 compressed stream that triggers a buffer overflow, a related issue to CVE-2009-1391.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs542777

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libcompress-raw-bzip2-perl (PTS)buster2.084-1fixed
bullseye2.101-1fixed
bookworm2.204-1fixed
sid, trixie2.212-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libcompress-raw-bzip2-perlsourcelenny2.011-2lenny1
libcompress-raw-bzip2-perlsource(unstable)2.018-1medium542777

Search for package or bug name: Reporting problems