FlawAtlas
Search the atlas
CVE-2019-12900 Critical

CVE-2019-12900

BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.

Exploit probability 8.1%
Published June 19, 2019
Required by Not available
Last source change August 7, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown
Hackage bz2

9 explicit affected versions

Hackage bzlib

10 explicit affected versions

Hackage bzlib-conduit

12 explicit affected versions

Unknown Unknown

300 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities HSEC-2024-0002

# out-of-bounds write when there are many bzip2 selectors A malicious bzip2 payload may produce a memory corruption resulting in a denial of service and/or remote code execution. Network services or command line utilities decompressing untrusted bzip2 payloads are affected. Note that the exploitation of this bug relies on an undefined behavior that appears to be handled safely by current compilers. The Haskell libraires are vulnerable when they are built using the bundled C library source code, which is the default in most cases.

View original source
Open Source Vulnerabilities PSF-2019-4

BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.

View original source
Open Source Vulnerabilities CVE-2019-12900

BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.

View original source

05 / REFERENCES

Further evidence