{"id":"CVE-2023-29417","details":"An issue was discovered in libbzip3.a in bzip3 1.2.2. There is a bz3_decompress out-of-bounds read in certain situations where buffers passed to bzip3 do not contain enough space to be filled with decompressed data. NOTE: the vendor's perspective is that the observed behavior can only occur for a contract violation, and thus the report is invalid.","modified":"2026-08-27T03:57:00.997229468Z","published":"2023-04-06T00:00:00Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/29xxx/CVE-2023-29417.json","cna_assigner":"mitre","isDisputed":true},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/29xxx/CVE-2023-29417.json"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4JLSE25SV7K2NB6FTFT4UHJOJUHBHYHY/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NA7S7HDUAINOTCSWQZ5LIW756DYY22V2/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NMLFV2FJK3CM7NJLVPZI5RUAFQZICPWW/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-29417"},{"type":"REPORT","url":"https://github.com/kspalaiologos/bzip3/issues/97"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/iczelia/bzip3","events":[{"introduced":"7b45d730f9e921bea9a9315ed43a09825bf7bd1b"},{"last_affected":"7b45d730f9e921bea9a9315ed43a09825bf7bd1b"}],"database_specific":{"source":"CPE_STRING","cpe":"cpe:2.3:a:bzip3_project:bzip3:1.2.2:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.2.2"},{"last_affected":"1.2.2"}]}}],"versions":["1.2.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-29417.json"}}],"schema_version":"1.9.0"}