CVE-2009-1884
Title: Perl Memory Corruption
Memory Corruption
Proof Of Concept
No public PoC currently indexed for CVE-2009-1884.
CWE Category
CWE-189
Published Date
Aug 19, 2009
Modified Date
Jun 16, 2026
Exploit Status
Not Found
Score
4.3
CVSS v2.0
Exploit Probability (EPSS)
2.59%
Vulnerability Summary
CVE-2009-1884: Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attackers to cause a denial of service (application hang or crash) via a crafted bzip2 compressed stream that triggers a buffer overflow, a related issue to CVE-2009-1391.
Impacted Vendors
Reference Links
http://secunia.com/advisories/36386
http://secunia.com/advisories/36415
http://security.gentoo.org/glsa/glsa-200908-07.xml
http://www.securityfocus.com/bid/36082
https://bugs.gentoo.org/show_bug.cgi?id=281955
https://bugzilla.redhat.com/show_bug.cgi?id=518278
https://exchange.xforce.ibmcloud.com/vulnerabilities/52628
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00982.html
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00999.html
http://secunia.com/advisories/36386
http://secunia.com/advisories/36415
http://security.gentoo.org/glsa/glsa-200908-07.xml
http://www.securityfocus.com/bid/36082
https://bugs.gentoo.org/show_bug.cgi?id=281955
https://bugzilla.redhat.com/show_bug.cgi?id=518278
https://exchange.xforce.ibmcloud.com/vulnerabilities/52628
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00982.html
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00999.html
CVSS v2.0
Source Entity
[email protected]
Severity
MEDIUM
4.3
Access Vector
N/A
Authentication
N/A
RAW VECTOR
AV:N/AC:M/Au:N/C:N/I:N/A:P
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2009-1884 Exploits & PoCs (Proof Of Concept)
No public PoCs found in our database for this CVE.
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data or affected products updated.
PUBLISHED
Vulnerability first announced in NVD.
Attack Vector Matrix
Access Vector
N/A
Complexity
N/A
Privileges
N/A
Interaction
NONE
CVSS Vector String
AV:N/AC:M/Au:N/C:N/I:N/A:P
Affected Stack
No specific products linked.