PublicDate: 2008-03-18 21:44:00 UTC Candidate: CVE-2008-1372 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1372 https://ubuntu.com/security/notices/USN-590-1 Description: bzlib.c in bzip2 before 1.0.5 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted file that triggers a buffer over-read, as demonstrated by the PROTOS GENOME test suite for Archive Formats. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_bzip2: upstream_bzip2: released (1.0.5) dapper_bzip2: released (1.0.3-0ubuntu2.1) edgy_bzip2: released (1.0.3-3ubuntu0.1) feisty_bzip2: released (1.0.3-6ubuntu0.1) gutsy_bzip2: released (1.0.4-0ubuntu2.1) devel_bzip2: released (1.0.4-2ubuntu4)