cbcvebase.
CVE-2018-10195
published 2021-06-02

CVE-2018-10195: lrzsz before version 0.12.21~rc can leak information to the receiving side due to an incorrect length check in the function zsdata that causes a size_t to wrap…

high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
lrzsz before version 0.12.21~rc can leak information to the receiving side due to an incorrect length check in the function zsdata that causes a size_t to wrap around.

Affected

12 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlrzsz< lrzsz 0.12.21-10 (bookworm)lrzsz 0.12.21-10 (bookworm)
lrzsz_projectlrzsz<= 0.12.20
lrzsz_projectlrzsz>= 0 < 0.12.21-100.12.21-10
lrzsz_projectlrzsz>= 0 < 0.12.21-100.12.21-10
lrzsz_projectlrzsz>= 0 < 0.12.21-100.12.21-10
lrzsz_projectlrzsz>= 0 < 0.12.21-100.12.21-10
msrccbl2_lrzsz_0.12.20-50_on_cbl_mariner_2.0
suselinux_enterprise_debuginfo
suselinux_enterprise_desktop
suselinux_enterprise_server
suselinux_enterprise_server

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH