JLSEC-2025-10

Source
https://github.com/JuliaLang/SecurityAdvisories.jl/blob/main/advisories/published/2025/JLSEC-2025-10.md
Import Source
https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2025/JLSEC-2025-10.json
JSON Data
https://api.osv.dev/v1/vulns/JLSEC-2025-10
Upstream
Published
2025-10-09T21:46:55.585Z
Modified
2025-11-06T23:02:25.356830Z
Summary
Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denia...
Details

Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2 file, related to block ends set to before the start of the block.

Database specific
{
    "sources": [
        {
            "modified": "2025-06-09T16:15:25.307Z",
            "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2016-3189",
            "id": "CVE-2016-3189",
            "imported": "2025-10-09T21:41:14.265Z",
            "html_url": "https://nvd.nist.gov/vuln/detail/CVE-2016-3189",
            "published": "2016-06-30T17:59:01.470Z"
        }
    ],
    "license": "CC-BY-4.0"
}
References

Affected packages

Julia / Bzip2_jll

Package

Name
Bzip2_jll
Purl
pkg:julia/Bzip2_jll?uuid=6e34b625-4abd-537c-b88f-471c36dfa7a0

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.7+0

Julia / Python_jll

Package

Name
Python_jll
Purl
pkg:julia/Python_jll?uuid=93d3a430-8e7c-50da-8e8d-3dfcfb3baf05

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.10.7+0