Debian 10230 Published by

Updated bzip2 packages has been released for both Debian GNU/Linux 7 Extended LTS and Debian GNU/Linux 8 LTS to address a regression introduced by the previous updates:

ELA-132-2: bzip2 regression update
DLA 1833-2: bzip2 regression update



ELA-132-2: bzip2 regression update

Package: bzip2
Related CVE: CVE-2019-12900

The original fix for CVE-2019-12900 introduces regressions when extracting certain lbzip2 files which were created with a buggy libzip2: https://bugs.debian.org/931278

We recommend that you upgrade your bzip2 packages.

Further information about Extended LTS security advisories can be found at: https://deb.freexian.com/extended-lts/

DLA 1833-2: bzip2 regression update

Package : bzip2
Version : 1.0.6-4+deb7u2
CVE ID : CVE-2019-12900

The original fix for CVE-2019-12900 in bzip2, a high-quality
block-sorting file compressor, introduces regressions when extracting
certain lbzip2 files which were created with a buggy libzip2.
Please see https://bugs.debian.org/931278 for more information.

For Debian 8 "Jessie", this problem has been fixed in version
1.0.6-4+deb7u2.

We recommend that you upgrade your bzip2 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS