An issue was discovered in libbzip3.a in bzip3 before 1.2.3. There is a crash caused by an invalid memmove in bz3decodeblock.
[
{
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2023-29420-c1508cb8",
"target": {
"function": "bz3_decode_block",
"file": "src/libbz3.c"
},
"signature_type": "Function",
"digest": {
"length": 2428.0,
"function_hash": "78927651910423473054068276738405572694"
},
"source": "https://github.com/iczelia/bzip3/commit/bb06deb85f1c249838eb938e0dab271d4194f8fa"
},
{
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2023-29420-f8920d99",
"target": {
"file": "src/libbz3.c"
},
"signature_type": "Line",
"digest": {
"line_hashes": [
"176151160024430871228388812718175632404",
"148928673947002201083747821524943350945",
"305471874631366783360112357820524980417",
"90638596750532673362592108567729244609"
],
"threshold": 0.9
},
"source": "https://github.com/iczelia/bzip3/commit/bb06deb85f1c249838eb938e0dab271d4194f8fa"
}
]