Updated bzip2 packages has been released for both Debian GNU/Linux 7 Extended LTS and Debian GNU/Linux 8 LTS to address a regression introduced by the previous updates:
ELA-132-2: bzip2 regression update
DLA 1833-2: bzip2 regression update
ELA-132-2: bzip2 regression update
DLA 1833-2: bzip2 regression update
ELA-132-2: bzip2 regression update
Package: bzip2
Related CVE: CVE-2019-12900
The original fix for CVE-2019-12900 introduces regressions when extracting certain lbzip2 files which were created with a buggy libzip2: https://bugs.debian.org/931278
We recommend that you upgrade your bzip2 packages.
Further information about Extended LTS security advisories can be found at: https://deb.freexian.com/extended-lts/
DLA 1833-2: bzip2 regression update
Package : bzip2
Version : 1.0.6-4+deb7u2
CVE ID : CVE-2019-12900
The original fix for CVE-2019-12900 in bzip2, a high-quality
block-sorting file compressor, introduces regressions when extracting
certain lbzip2 files which were created with a buggy libzip2.
Please see https://bugs.debian.org/931278 for more information.
For Debian 8 "Jessie", this problem has been fixed in version
1.0.6-4+deb7u2.
We recommend that you upgrade your bzip2 packages.
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS