Security Advisories (2)
CVE-2010-0405 (2010-01-27)

Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 before 1.0.6 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted compressed file.

CVE-2009-1884 (2009-08-19)

Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attackers to cause a denial of service (application hang or crash) via a crafted bzip2 compressed stream that triggers a buffer overflow, a related issue to CVE-2009-1391.

Documentation

Frequently Asked Questions about Compress::Raw::Bzip2

Modules

Low-Level Interface to bzip2 compression library

Provides

in lib/Compress/Raw/Bzip2.pm
in private/MakeUtil.pm