DEBIAN-CVE-2011-4089

Source
https://security-tracker.debian.org/tracker/CVE-2011-4089
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2011-4089.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2011-4089
Upstream
Published
2014-04-16T18:37:11Z
Modified
2026-09-14T06:47:25Z
Summary
[none]
Details

The bzexe command in bzip2 1.0.5 and earlier generates compressed executables that do not properly handle temporary files during extraction, which allows local users to execute arbitrary code by precreating a temporary directory.

References

Affected packages

Debian:12 / bzip2

Package

Name
bzip2
Purl
pkg:deb/debian/bzip2?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.0.6-1

Ecosystem specific

{
    "urgency": "low"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2011-4089.json"

Debian:13 / bzip2

Package

Name
bzip2
Purl
pkg:deb/debian/bzip2?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.0.6-1

Ecosystem specific

{
    "urgency": "low"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2011-4089.json"

Debian:14 / bzip2

Package

Name
bzip2
Purl
pkg:deb/debian/bzip2?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.0.6-1

Ecosystem specific

{
    "urgency": "low"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2011-4089.json"