An issue was discovered in libbzip3.a in bzip3 before 1.3.0. A bz3decodeblock out-of-bounds write can occur with a crafted archive because bzip3 does not follow the required procedure for interacting with libsais.
[
{
"id": "CVE-2023-29416-19905069",
"target": {
"function": "bz3_decode_block",
"file": "src/libbz3.c"
},
"digest": {
"length": 2428.0,
"function_hash": "78091232806249023319376770793511546684"
},
"signature_version": "v1",
"deprecated": false,
"source": "https://github.com/iczelia/bzip3/commit/bfa5bf82b53715dfedf048e5859a46cf248668ff",
"signature_type": "Function"
},
{
"id": "CVE-2023-29416-e55fa4c8",
"target": {
"file": "src/libbz3.c"
},
"digest": {
"line_hashes": [
"135116326092922409152670506071334723654",
"90305454055684765824126621358253644746",
"166235600926289558465095286270088250222",
"314479395042320166331311193867135742067",
"187789211931984610138552945721024261022",
"85961195397637187652091149137428860886",
"160460775484721881840794065466199923175",
"287491035869953310141276074854768989691"
],
"threshold": 0.9
},
"signature_version": "v1",
"deprecated": false,
"source": "https://github.com/iczelia/bzip3/commit/bfa5bf82b53715dfedf048e5859a46cf248668ff",
"signature_type": "Line"
},
{
"id": "CVE-2023-29416-f9d58be4",
"target": {
"function": "bz3_new",
"file": "src/libbz3.c"
},
"digest": {
"length": 928.0,
"function_hash": "93144664967161454149050858396074407075"
},
"signature_version": "v1",
"deprecated": false,
"source": "https://github.com/iczelia/bzip3/commit/bfa5bf82b53715dfedf048e5859a46cf248668ff",
"signature_type": "Function"
}
]