CVE-2017-8844
published 2017-05-08CVE-2017-8844: The read_1g function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (heap-based buffer overflow and application…
high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
The read_1g function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted archive.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ckolivas | lrzip | >= 0 < 0.631+git180517-1 | 0.631+git180517-1 |
| ckolivas | lrzip | >= 0 < 0.631+git180517-1 | 0.631+git180517-1 |
| ckolivas | lrzip | >= 0 < 0.631+git180517-1 | 0.631+git180517-1 |
| ckolivas | lrzip | >= 0 < 0.631+git180517-1 | 0.631+git180517-1 |
| debian | debian_linux | — | — |
| debian | lrzip | < lrzip 0.631+git180517-1 (bookworm) | lrzip 0.631+git180517-1 (bookworm) |
| long_range_zip_project | long_range_zip | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH