BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.
{ "vanir_signatures": [ { "signature_type": "Line", "digest": { "line_hashes": [ "193662908927078745708702042109529205902", "16813243021549239572194252372936960661", "154544188480167473863108834568414589177", "294592855379212741126804546922529497937" ], "threshold": 0.9 }, "signature_version": "v1", "source": "https://gitlab.com/federicomenaquintero/bzip2@74de1e2e6ffc9d51ef9824db71a8ffee5962cdbc", "id": "CVE-2019-12900-85543407", "target": { "file": "decompress.c" }, "deprecated": false }, { "signature_type": "Function", "digest": { "length": 13498.0, "function_hash": "188338681100398363911181230312621404683" }, "signature_version": "v1", "source": "https://gitlab.com/federicomenaquintero/bzip2@74de1e2e6ffc9d51ef9824db71a8ffee5962cdbc", "id": "CVE-2019-12900-fedadc1c", "target": { "function": "BZ2_decompress", "file": "decompress.c" }, "deprecated": false } ] }