cbcvebase.
CVE-2017-8844
published 2017-05-08

CVE-2017-8844: The read_1g function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (heap-based buffer overflow and application…

high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
The read_1g function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted archive.

Affected

7 ranges
VendorProductVersion rangeFixed in
ckolivaslrzip>= 0 < 0.631+git180517-10.631+git180517-1
ckolivaslrzip>= 0 < 0.631+git180517-10.631+git180517-1
ckolivaslrzip>= 0 < 0.631+git180517-10.631+git180517-1
ckolivaslrzip>= 0 < 0.631+git180517-10.631+git180517-1
debiandebian_linux
debianlrzip< lrzip 0.631+git180517-1 (bookworm)lrzip 0.631+git180517-1 (bookworm)
long_range_zip_projectlong_range_zip

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH