CVE-2016-3189 PUBLISHED

Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2 file, related to block ends set to before the start of the block.

EPSS 24.18% · 96.0th percentile

Risk Scores

EPSS Score
24.18%
96.0th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSbzip20, 1.0.6-8
Ubuntu:Pro:14.04:LTSbzip20, 1.0.6-4, 1.0.6-5

Timeline

References

Open in Interactive Console →