An issue was discovered in libbzip3.a in bzip3 before 1.2.3. There is an xwrite out-of-bounds read.
[ { "deprecated": false, "source": "https://github.com/iczelia/bzip3/commit/aae16d107f804f69000c09cd92027a140968cc9d", "signature_type": "Line", "id": "CVE-2023-29418-178fcd24", "target": { "file": "src/main.c" }, "digest": { "line_hashes": [ "211831818964014856103622541363650679657", "200037471870026598278383769173116107817", "26720059851685332351195084736727559975", "241660204824741965093415854272803110828", "211831818964014856103622541363650679657", "200037471870026598278383769173116107817", "26720059851685332351195084736727559975", "241660204824741965093415854272803110828", "131922326679721282732499408615967976224", "335159807458322304546125530079614390824", "88891182250321558557571543551209637252", "713681647917464116366090269796584334", "131922326679721282732499408615967976224", "335159807458322304546125530079614390824", "88891182250321558557571543551209637252", "713681647917464116366090269796584334", "181126335907423172246662450242202043802", "323433510319311865688013523949882147088", "195639911689088271451460309311575813105" ], "threshold": 0.9 }, "signature_version": "v1" }, { "deprecated": false, "source": "https://github.com/iczelia/bzip3/commit/aae16d107f804f69000c09cd92027a140968cc9d", "signature_type": "Function", "id": "CVE-2023-29418-24b49b32", "target": { "file": "src/main.c", "function": "process" }, "digest": { "length": 6254.0, "function_hash": "259921278180978118086864396290996536086" }, "signature_version": "v1" }, { "deprecated": false, "source": "https://github.com/iczelia/bzip3/commit/aae16d107f804f69000c09cd92027a140968cc9d", "signature_type": "Function", "id": "CVE-2023-29418-24bd3114", "target": { "file": "src/main.c", "function": "main" }, "digest": { "length": 4876.0, "function_hash": "298063098834418908807228916248020768633" }, "signature_version": "v1" }, { "deprecated": false, "source": "https://github.com/iczelia/bzip3/commit/aae16d107f804f69000c09cd92027a140968cc9d", "signature_type": "Line", "id": "CVE-2023-29418-e3353bef", "target": { "file": "src/libbz3.c" }, "digest": { "line_hashes": [ "275810663828927352826613709065358077708", "38873639147903593833839701801921452536", "12935270000953913742254829221233255797", "320536092246239784510143637813552743647", "33251863310640770226447460402420981629" ], "threshold": 0.9 }, "signature_version": "v1" } ]