CVE-2016-3189

Severity

43%

Complexity

86%

Confidentiality

48%

CWE-416: Use After Free

Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2 file, related to block ends set to before the start of the block.

CWE-416: Use After Free

CVSS 3.0 Base Score 6.5. CVSS Attack Vector: network. CVSS Attack Complexity: low. CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).

CVSS 2.0 Base Score 4.3. CVSS Attack Vector: network. CVSS Attack Complexity: medium. CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P).

Overview

First reported 8 years ago

2016-06-30 17:59:00

Last updated 7 years ago

2017-08-22 01:29:00

Affected Software

bzip bzip2 1.0.6

1.0.6

References

http://packetstormsecurity.com/files/153644/Slackware-Security-Advisory-bzip2-Updates.html

http://packetstormsecurity.com/files/153957/FreeBSD-Security-Advisory-FreeBSD-SA-19-18.bzip2.html

[oss-security] 20160620 CVE-2016-3189: bzip2 use-after-free on bzip2recover

http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html

91297

1036132

https://bugzilla.redhat.com/show_bug.cgi?id=1319648

[kafka-jira] 20200414 [jira] [Commented] (KAFKA-9858) CVE-2016-3189 Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2 file, related to block ends set to before the start of the block.

[kafka-jira] 20200413 [jira] [Created] (KAFKA-9858) CVE-2016-3189 Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2 file, related to block ends set to before the start of the block.

[kafka-jira] 20200413 [jira] [Updated] (KAFKA-9858) CVE-2016-3189 Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2 file, related to block ends set to before the start of the block.

[kafka-users] 20200413 CVEs for the dependency software guava and rocksdbjni of Kafka

[kafka-dev] 20200413 [jira] [Created] (KAFKA-9858) CVE-2016-3189 Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2 file, related to block ends set to before the start of the block.

[debian-lts-announce] 20190624 [SECURITY] [DLA 1833-1] bzip2 security update

20190806 FreeBSD Security Advisory FreeBSD-SA-19:18.bzip2

20190715 [slackware-security] bzip2 (SSA:2019-195-01)

FreeBSD-SA-19:18

GLSA-201708-08

USN-4038-1

USN-4038-2

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.