Use-after-free memory corruption in bzip2recover in bzip2 - CVE-2016-3189
Published: June 21, 2016 / Updated: July 8, 2016
Vulnerability details
The vulnerability allows a remote attacker to cause the target application to crash.
The vulnerability exists due to an use-after-free error in bzip2recover when handling bzip2 files. A remote unauthenticated attacker can send a specially crafted bzip2 archive and cause the target application to crash.
Successful exploitation of this vulnerability will result in denial of service.
Affected software
Gentoo Linux
Arch Linux
FreeBSD
Slackware Linux
Opensuse
Fedora
bzip2 (Alpine package)
bzip2
Dell EMC AppSync
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
IBM License Metric Tool
How to mitigate CVE-2016-3189
bzip2 - addressed in versions 1.0.6-21.fc24, 1.0.6-21.fc25
Dell EMC AppSync - update to 4.4.1.0
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.2.0.5.009
Dell EMC Unity XT Operating Environment (OE) - update to 5.0.2.0.5.009
Dell EMC Unity Operating Environment (OE) - update to 5.0.2.0.5.009
IBM License Metric Tool - update to 9.2.34
External References
Related Security Bulletins
- Use-after-free in bzip2
- Arch Linux update for bzip2
- Gentoo update for bzip2
- OpenSUSE Linux update for bzip2
- OpenSUSE Linux update for bzip2
- Slackware Linux update for bzip2
- Multiple vulnerabilities in FreeBSD
- Use-after-free memory corruption in bzip2recover in bzip2 (Alpine package)
- Multiple vulnerabilities in Dell EMC AppSync
- Multiple vulnerabilities in Dell EMC Unity Family, Dell EMC Unity XT Family
- IBM License Metric Tool update for bzip2
- Fedora 25 update for bzip2
- Fedora 24 update for bzip2