BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.
{
"unresolved_ranges": [
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:bzip:bzip2:*:*:*:*:*:*:*:*"
],
"vendor_product": "bzip:bzip2",
"extracted_events": [
{
"last_affected": "1.0.6"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:*:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*"
],
"vendor_product": "canonical:ubuntu_linux",
"extracted_events": [
{
"last_affected": "12.04"
},
{
"last_affected": "14.04"
},
{
"last_affected": "16.04"
},
{
"last_affected": "18.04"
},
{
"last_affected": "19.04"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
],
"vendor_product": "debian:debian_linux",
"extracted_events": [
{
"last_affected": "8.0"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:o:freebsd:freebsd:11.2:-:*:*:*:*:*:*",
"cpe:2.3:o:freebsd:freebsd:11.2:p10:*:*:*:*:*:*",
"cpe:2.3:o:freebsd:freebsd:11.2:p11:*:*:*:*:*:*",
"cpe:2.3:o:freebsd:freebsd:11.2:p12:*:*:*:*:*:*",
"cpe:2.3:o:freebsd:freebsd:11.2:p2:*:*:*:*:*:*",
"cpe:2.3:o:freebsd:freebsd:11.2:p3:*:*:*:*:*:*",
"cpe:2.3:o:freebsd:freebsd:11.2:p4:*:*:*:*:*:*",
"cpe:2.3:o:freebsd:freebsd:11.2:p5:*:*:*:*:*:*",
"cpe:2.3:o:freebsd:freebsd:11.2:p6:*:*:*:*:*:*",
"cpe:2.3:o:freebsd:freebsd:11.2:p7:*:*:*:*:*:*",
"cpe:2.3:o:freebsd:freebsd:11.2:p8:*:*:*:*:*:*",
"cpe:2.3:o:freebsd:freebsd:11.2:p9:*:*:*:*:*:*",
"cpe:2.3:o:freebsd:freebsd:11.2:rc3:*:*:*:*:*:*",
"cpe:2.3:o:freebsd:freebsd:11.3:-:*:*:*:*:*:*",
"cpe:2.3:o:freebsd:freebsd:11.3:p1:*:*:*:*:*:*",
"cpe:2.3:o:freebsd:freebsd:12.0:-:*:*:*:*:*:*",
"cpe:2.3:o:freebsd:freebsd:12.0:p1:*:*:*:*:*:*",
"cpe:2.3:o:freebsd:freebsd:12.0:p2:*:*:*:*:*:*",
"cpe:2.3:o:freebsd:freebsd:12.0:p3:*:*:*:*:*:*",
"cpe:2.3:o:freebsd:freebsd:12.0:p4:*:*:*:*:*:*",
"cpe:2.3:o:freebsd:freebsd:12.0:p5:*:*:*:*:*:*",
"cpe:2.3:o:freebsd:freebsd:12.0:p6:*:*:*:*:*:*",
"cpe:2.3:o:freebsd:freebsd:12.0:p7:*:*:*:*:*:*",
"cpe:2.3:o:freebsd:freebsd:12.0:p8:*:*:*:*:*:*"
],
"vendor_product": "freebsd:freebsd",
"extracted_events": [
{
"last_affected": "11.2-NA"
},
{
"last_affected": "11.2-p10"
},
{
"last_affected": "11.2-p11"
},
{
"last_affected": "11.2-p12"
},
{
"last_affected": "11.2-p2"
},
{
"last_affected": "11.2-p3"
},
{
"last_affected": "11.2-p4"
},
{
"last_affected": "11.2-p5"
},
{
"last_affected": "11.2-p6"
},
{
"last_affected": "11.2-p7"
},
{
"last_affected": "11.2-p8"
},
{
"last_affected": "11.2-p9"
},
{
"last_affected": "11.2-rc3"
},
{
"last_affected": "11.3-NA"
},
{
"last_affected": "11.3-p1"
},
{
"last_affected": "12.0-NA"
},
{
"last_affected": "12.0-p1"
},
{
"last_affected": "12.0-p2"
},
{
"last_affected": "12.0-p3"
},
{
"last_affected": "12.0-p4"
},
{
"last_affected": "12.0-p5"
},
{
"last_affected": "12.0-p6"
},
{
"last_affected": "12.0-p7"
},
{
"last_affected": "12.0-p8"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*",
"cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*"
],
"vendor_product": "opensuse:leap",
"extracted_events": [
{
"last_affected": "15.0"
},
{
"last_affected": "15.1"
}
]
}
]
}