Bzip2
—
filed under:
Security
bzlib.c in bzip2 before 1.0.5 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted file that triggers a buffer over-read, as demonstrated by the PROTOS GENOME test suite for Archive Formats.
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1372
New bzip2 package is available for Vector Linux 5.9


