CVE-2016-3189
MEDIUMBzip2 < 3.7.13 - Use After Free
Title source: ruleDescription
Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2 file, related to block ends set to before the start of the block.
References (25)
... and 5 more
Scores
CVSS v3
6.5
EPSS
0.2371
EPSS Percentile
95.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Classification
CWE
CWE-416
Status
draft
Affected Products (2)
bzip/bzip2
python/python
< 3.7.13
Timeline
Published
Jun 30, 2016
Tracked Since
Feb 18, 2026