{"id":"JLSEC-2025-11","summary":"BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many...","details":"BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.","modified":"2025-11-03T00:18:35.123490Z","published":"2025-10-09T21:46:55.585Z","upstream":["CVE-2019-12900"],"database_specific":{"license":"CC-BY-4.0","sources":[{"id":"CVE-2019-12900","published":"2019-06-19T23:15:09.910Z","modified":"2025-06-09T16:15:29.623Z","url":"https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2019-12900","html_url":"https://nvd.nist.gov/vuln/detail/CVE-2019-12900","imported":"2025-10-09T21:41:14.269Z"}]},"references":[{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00040.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00050.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00078.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00000.html"},{"type":"WEB","url":"http://packetstormsecurity.com/files/153644/Slackware-Security-Advisory-bzip2-Updates.html"},{"type":"WEB","url":"http://packetstormsecurity.com/files/153957/FreeBSD-Security-Advisory-FreeBSD-SA-19-18.bzip2.html"},{"type":"WEB","url":"https://gitlab.com/federicomenaquintero/bzip2/commit/74de1e2e6ffc9d51ef9824db71a8ffee5962cdbc"},{"type":"WEB","url":"https://lists.apache.org/thread.html/ra0adb9653c7de9539b93cc8434143b655f753b9f60580ff260becb2b%40%3Cusers.kafka.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rce8cd8c30f60604b580ea01bebda8a671a25c9a1629f409fc24e7774%40%3Cuser.flink.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rda98305669476c4d90cc8527c4deda7e449019dd1fe9936b56671dd4%40%3Cuser.flink.apache.org%3E"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2019/06/msg00021.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2019/07/msg00014.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2019/10/msg00012.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2019/10/msg00018.html"},{"type":"WEB","url":"https://seclists.org/bugtraq/2019/Aug/4"},{"type":"WEB","url":"https://seclists.org/bugtraq/2019/Jul/22"},{"type":"WEB","url":"https://security.FreeBSD.org/advisories/FreeBSD-SA-19:18.bzip2.asc"},{"type":"WEB","url":"https://support.f5.com/csp/article/K68713584?utm_source=f5support&amp%3Butm_medium=RSS"},{"type":"WEB","url":"https://usn.ubuntu.com/4038-1/"},{"type":"WEB","url":"https://usn.ubuntu.com/4038-2/"},{"type":"WEB","url":"https://usn.ubuntu.com/4146-1/"},{"type":"WEB","url":"https://usn.ubuntu.com/4146-2/"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuoct2020.html"}],"affected":[{"package":{"name":"Bzip2_jll","ecosystem":"Julia","purl":"pkg:julia/Bzip2_jll?uuid=6e34b625-4abd-537c-b88f-471c36dfa7a0"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.0.7+0"}]}],"database_specific":{"source":"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2025/JLSEC-2025-11.json"}},{"package":{"name":"Python_jll","ecosystem":"Julia","purl":"pkg:julia/Python_jll?uuid=93d3a430-8e7c-50da-8e8d-3dfcfb3baf05"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.10.7+0"}]}],"database_specific":{"source":"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2025/JLSEC-2025-11.json"}}],"schema_version":"1.7.3"}