BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.
[
{
"id": "CVE-2019-12900-85543407",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "decompress.c"
},
"source": "https://gitlab.com/federicomenaquintero/bzip2@74de1e2e6ffc9d51ef9824db71a8ffee5962cdbc",
"digest": {
"line_hashes": [
"193662908927078745708702042109529205902",
"16813243021549239572194252372936960661",
"154544188480167473863108834568414589177",
"294592855379212741126804546922529497937"
],
"threshold": 0.9
},
"signature_type": "Line"
},
{
"id": "CVE-2019-12900-fedadc1c",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "decompress.c",
"function": "BZ2_decompress"
},
"source": "https://gitlab.com/federicomenaquintero/bzip2@74de1e2e6ffc9d51ef9824db71a8ffee5962cdbc",
"digest": {
"length": 13498.0,
"function_hash": "188338681100398363911181230312621404683"
},
"signature_type": "Function"
}
]