Out-of-bounds write in bzip2 - CVE-2019-12900
Published: July 15, 2019
Vulnerability identifier: #VU19178
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-12900
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the BZ2_decompress() function in decompress.c. A remote attacker can create a specially crafted archive, trick the victim into opening it using the affected library, trigger out-of-bounds write and execute arbitrary code on the target system.
Affected software
bzip2
Submariner
IBM Concert Software
Netcool Operations Insight
IBM Power Hardware Management Console (HMC)
Service Interconnect
Multicluster GlobalHub
Red Hat Integration Camel-K
Red Hat Advanced Cluster Management for Kubernetes
Red Hat OpenShift Dev Spaces
Red Hat Advanced Cluster Security for Kubernetes
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
OpenShift Logging
Red Hat OpenStack
ClamAV
bzip2 (Alpine package)
clamav
bzip2
bzip2-devel
bzip2-libs
bzip2-static
bzip2 (Red Hat package)
watsonx.data
Guardium Data Security Center (GDSC)
IBM Cloud Pak for Watson AIOps
Robotic Process Automation for Cloud Pak
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
Watson Studio on Cloud Pak for Data
IBM QRadar Incident Forensics
Fedora
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
FreeBSD
Slackware Linux
Opensuse
IBM API Connect
Oracle Database Server
Red Hat OpenShift Serverless
Multicluster Engine for Kubernetes
OpenShift Service Mesh
OpenShift Data Foundation (formerly OpenShift Container Storage)
OpenShift Virtualization
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Dell EMC AppSync
RSA Authentication Manager
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
IBM Qradar SIEM
IBM License Metric Tool
Juniper Secure Analytics (JSA)
Red Hat Ceph Storage
Submariner
IBM Concert Software
Netcool Operations Insight
IBM Power Hardware Management Console (HMC)
Service Interconnect
Multicluster GlobalHub
Red Hat Integration Camel-K
Red Hat Advanced Cluster Management for Kubernetes
Red Hat OpenShift Dev Spaces
Red Hat Advanced Cluster Security for Kubernetes
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
OpenShift Logging
Red Hat OpenStack
ClamAV
bzip2 (Alpine package)
clamav
bzip2
bzip2-devel
bzip2-libs
bzip2-static
bzip2 (Red Hat package)
watsonx.data
Guardium Data Security Center (GDSC)
IBM Cloud Pak for Watson AIOps
Robotic Process Automation for Cloud Pak
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
Watson Studio on Cloud Pak for Data
IBM QRadar Incident Forensics
Fedora
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
FreeBSD
Slackware Linux
Opensuse
IBM API Connect
Oracle Database Server
Red Hat OpenShift Serverless
Multicluster Engine for Kubernetes
OpenShift Service Mesh
OpenShift Data Foundation (formerly OpenShift Container Storage)
OpenShift Virtualization
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Dell EMC AppSync
RSA Authentication Manager
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
IBM Qradar SIEM
IBM License Metric Tool
Juniper Secure Analytics (JSA)
Red Hat Ceph Storage
How to mitigate CVE-2019-12900
Install update from vendor's website.
Submariner - addressed in versions 0.16.8, 0.18.5
ClamAV - update to 0.101.4
IBM Concert Software - update to 1.1.0
bzip2 (Alpine package) - update to 1.0.6-r7
Netcool Operations Insight - update to 1.6.15
watsonx.data - update to 2.1.2
Guardium Data Security Center (GDSC) - update to 3.6.1
IBM Cloud Pak for Watson AIOps - update to 4.10.0
IBM API Connect - update to 10.0.8.2 ifix2
IBM Power Hardware Management Console (HMC) - addressed in versions 10.2.1040.0 SP3, 10.3.1060.0 SP1
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.21, 23.0.20.2
clamav - addressed in versions 0.101.4-1.el7, 0.101.4-1.el8, 0.101.4-1.fc29, 0.101.4-1.fc30
Service Interconnect - addressed in versions 1, 1.4
Red Hat OpenShift Serverless - update to 1
bzip2 - addressed in versions 1.0.6-27, 1.0.6-28
bzip2-devel - addressed in versions 1.0.6-27, 1.0.6-28
bzip2-libs - addressed in versions 1.0.6-27, 1.0.6-28
bzip2-static - addressed in versions 1.0.6-27, 1.0.6-28
bzip2 (Red Hat package) - addressed in versions 1.0.6-27.el8_10, 1.0.6-28.el8_10, 1.0.8-8.el9_4.1, 1.0.8-10.el9_5
Multicluster GlobalHub - update to 1.2.1
Migration Toolkit for Containers - update to 1.8.5
Red Hat Integration Camel-K - update to 1.10.9
Multicluster Engine for Kubernetes - addressed in versions 2.3.8, 2.4.7, 2.5.9, 2.6.7, 2.7.3, 2.7.4
OpenShift Service Mesh - addressed in versions 2.4.13, 2.4.14, 2.5.6, 2.5.7, 2.5.8, 2.6.5
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.8.8, 2.9.6, 2.10.7, 2.10.8, 2.11.4, 2.11.7, 2.12.2, 2.12.3
Red Hat OpenShift Dev Spaces - update to 3.17.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4
Dell EMC AppSync - update to 4.4.1.0
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.4.6, 4.4.8, 4.5.5, 4.6.2
DB2 on Cloud Pak for Data - update to 4.8.8
DB2 Warehouse on Cloud Pak for Data - update to 4.8.8
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.9
Watson Studio on Cloud Pak for Data - addressed in versions 4.8.9, 5.1.2
OpenShift Virtualization - addressed in versions 4.13.11, 4.15.9, 4.16.7, 4.17.3
Red Hat OpenShift Container Platform - addressed in versions 4.14.41, 4.14.46, 4.15.38, 4.16.44, 4.19.0
Dell EMC Unity XT Operating Environment (OE) - update to 5.0.2.0.5.009
Dell EMC Unity Operating Environment (OE) - update to 5.0.2.0.5.009
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.2.0.5.009
OpenShift Logging - addressed in versions 5.6.27, 5.8.17, 5.8.19, 5.8.20, 5.9.11, 5.9.14
IBM QRadar Incident Forensics - update to 7.5.0 UP10 IF02
IBM Qradar SIEM - update to 7.5.0 Update Pack 10 IF02
Juniper Secure Analytics (JSA) - update to 7.5.0 UP11 IF03
Red Hat Ceph Storage - update to 8.1
RSA Authentication Manager - addressed in versions 8.4 Patch 10, 8.5 Patch 3
IBM License Metric Tool - update to 9.2.34
Red Hat OpenStack - update to 16.2
ClamAV - update to 0.101.4
IBM Concert Software - update to 1.1.0
bzip2 (Alpine package) - update to 1.0.6-r7
Netcool Operations Insight - update to 1.6.15
watsonx.data - update to 2.1.2
Guardium Data Security Center (GDSC) - update to 3.6.1
IBM Cloud Pak for Watson AIOps - update to 4.10.0
IBM API Connect - update to 10.0.8.2 ifix2
IBM Power Hardware Management Console (HMC) - addressed in versions 10.2.1040.0 SP3, 10.3.1060.0 SP1
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.21, 23.0.20.2
clamav - addressed in versions 0.101.4-1.el7, 0.101.4-1.el8, 0.101.4-1.fc29, 0.101.4-1.fc30
Service Interconnect - addressed in versions 1, 1.4
Red Hat OpenShift Serverless - update to 1
bzip2 - addressed in versions 1.0.6-27, 1.0.6-28
bzip2-devel - addressed in versions 1.0.6-27, 1.0.6-28
bzip2-libs - addressed in versions 1.0.6-27, 1.0.6-28
bzip2-static - addressed in versions 1.0.6-27, 1.0.6-28
bzip2 (Red Hat package) - addressed in versions 1.0.6-27.el8_10, 1.0.6-28.el8_10, 1.0.8-8.el9_4.1, 1.0.8-10.el9_5
Multicluster GlobalHub - update to 1.2.1
Migration Toolkit for Containers - update to 1.8.5
Red Hat Integration Camel-K - update to 1.10.9
Multicluster Engine for Kubernetes - addressed in versions 2.3.8, 2.4.7, 2.5.9, 2.6.7, 2.7.3, 2.7.4
OpenShift Service Mesh - addressed in versions 2.4.13, 2.4.14, 2.5.6, 2.5.7, 2.5.8, 2.6.5
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.8.8, 2.9.6, 2.10.7, 2.10.8, 2.11.4, 2.11.7, 2.12.2, 2.12.3
Red Hat OpenShift Dev Spaces - update to 3.17.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4
Dell EMC AppSync - update to 4.4.1.0
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.4.6, 4.4.8, 4.5.5, 4.6.2
DB2 on Cloud Pak for Data - update to 4.8.8
DB2 Warehouse on Cloud Pak for Data - update to 4.8.8
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.9
Watson Studio on Cloud Pak for Data - addressed in versions 4.8.9, 5.1.2
OpenShift Virtualization - addressed in versions 4.13.11, 4.15.9, 4.16.7, 4.17.3
Red Hat OpenShift Container Platform - addressed in versions 4.14.41, 4.14.46, 4.15.38, 4.16.44, 4.19.0
Dell EMC Unity XT Operating Environment (OE) - update to 5.0.2.0.5.009
Dell EMC Unity Operating Environment (OE) - update to 5.0.2.0.5.009
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.2.0.5.009
OpenShift Logging - addressed in versions 5.6.27, 5.8.17, 5.8.19, 5.8.20, 5.9.11, 5.9.14
IBM QRadar Incident Forensics - update to 7.5.0 UP10 IF02
IBM Qradar SIEM - update to 7.5.0 Update Pack 10 IF02
Juniper Secure Analytics (JSA) - update to 7.5.0 UP11 IF03
Red Hat Ceph Storage - update to 8.1
RSA Authentication Manager - addressed in versions 8.4 Patch 10, 8.5 Patch 3
IBM License Metric Tool - update to 9.2.34
Red Hat OpenStack - update to 16.2
External References
Related Security Bulletins
- Slackware Linux update for bzip2
- OpenSUSE Linux update for bzip2
- Multiple vulnerabilities in FreeBSD
- OpenSUSE Linux update for bzip2
- Multiple vulnerabilities in ClamAV
- Out-of-bounds write in bzip2 (Alpine package)
- Multiple vulnerabilities in Oracle Database Server
- Multiple vulnerabilities in Dell EMC AppSync
- Multiple vulnerabilities in Dell EMC Unity Family, Dell EMC Unity XT Family
- IBM License Metric Tool update for bzip2
- Red Hat Enterprise Linux 8 update for bzip2
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.4
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in OpenShift Service Mesh 2.5
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.3
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.8
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.5
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces 3.17
- Multiple vulnerabilities in OpenShift Virtualization 4.13
- Red Hat Enterprise Linux 9 update for bzip2
- Multiple vulnerabilities in Red Hat OpenStack 16.2 packages
- Multiple vulnerabilities in Migration Toolkit for Containers 1.8
- Multiple vulnerabilities in OpenShift Service Mesh 2.4
- Multiple vulnerabilities in OpenShift Service Mesh 2.5
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.11
- Multiple vulnerabilities in OpenShift Virtualization 4.17
- Multiple vulnerabilities in OpenShift Logging 5.6
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.4
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.9
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.10
- Multiple vulnerabilities in Guardium Data Security Center
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.7
- Red Hat Enterprise Linux 8 update for bzip2
- Multiple vulnerabilities in Submariner
- Multiple vulnerabilities in Multicluster GlobalHub 1.2
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.12
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.6
- Red Hat Enterprise Linux 9 update for bzip2
- Multiple vulnerabilities in OpenShift Service Mesh 2.4
- Multiple vulnerabilities in OpenShift Service Mesh 2.5
- Multiple vulnerabilities in OpenShift Service Mesh 2.6
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat Integration Camel-K 1.10
- Multiple vulnerabilities in OpenShift Logging 5.9
- Multiple vulnerabilities in OpenShift Logging 5.8
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.4
- IBM Power Hardware Management Console (HMC) update for bzip2
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage)
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage)
- Multiple vulnerabilities in OpenShift Virtualization 4.15
- Anolis OS update for bzip2
- Anolis OS update for bzip2
- Multiple vulnerabilities in OpenShift Logging 5.8
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.7
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.12
- Multiple vulnerabilities in Service Interconnect
- Multiple vulnerabilities in OpenShift Virtualization 4.16
- Fedora 29 update for clamav
- Fedora 30 update for clamav
- Fedora EPEL 7 update for clamav
- Fedora EPEL 8 update for clamav
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.5
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.10
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.6
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.11
- Multiple vulnerabilities in Submariner 0.18
- Multiple vulnerabilities in OpenShift Logging 5.8
- Multiple vulnerabilities in OpenShift Logging 5.9
- Juniper Secure Analytics update for third-party components
- RSA Authentication Manager update for third-party components
- RSA Authentication Manager update for third-party components
- Multiple vulnerabilities in IBM Concert Software
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in IBM API Connect
- IBM watsonx.data update for BZ2_decompress
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.19
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Multiple vulnerabilities in Service Interconnect 1
- Multiple vulnerabilities in Red Hat Ceph Storage 8
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in IBM Watson Studio on Cloud Pak for Data
- Multiple vulnerabilities in Netcool Operations Insight