Ckolivas Lrzip vulnerabilities

23 known vulnerabilities affecting ckolivas/lrzip.

Total CVEs
23
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH1MEDIUM20

Vulnerabilities

Page 1 of 2
CVE-2025-15570MEDIUMCVSS 4.8≤ 0.651v0.6512026-02-10
CVE-2025-15570 [MEDIUM] CWE-119 CVE-2025-15570: A vulnerability was found in ckolivas lrzip up to 0.651. This impacts the function lzma_decompress_b A vulnerability was found in ckolivas lrzip up to 0.651. This impacts the function lzma_decompress_buf of the file stream.c. Performing a manipulation results in use after free. Attacking locally is a requirement. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not res
cvelistv5nvdosv
CVE-2025-15571MEDIUMCVSS 4.8≤ 0.651v0.6512026-02-10
CVE-2025-15571 [MEDIUM] CWE-404 CVE-2025-15571: A security vulnerability has been detected in ckolivas lrzip up to 0.651. This vulnerability affects A security vulnerability has been detected in ckolivas lrzip up to 0.651. This vulnerability affects the function ucompthread of the file stream.c. Such manipulation leads to null pointer dereference. The attack can only be performed from a local environment. The exploit has been disclosed publicly and may be used. The project was informed of the pr
cvelistv5nvdosv
CVE-2025-9396MEDIUMCVSS 4.8≤ 0.651v0.6512025-08-24
CVE-2025-9396 [MEDIUM] CWE-404 CVE-2025-9396: A security flaw has been discovered in ckolivas lrzip up to 0.651. This impacts the function __GI___ A security flaw has been discovered in ckolivas lrzip up to 0.651. This impacts the function __GI_____strtol_l_internal of the file strtol_l.c. Performing manipulation results in null pointer dereference. The attack is only possible with local access. The exploit has been released to the public and may be exploited.
cvelistv5nvd
CVE-2023-39741MEDIUMCVSS 5.5≥ 0, < 0.651-32023-08-17
CVE-2023-39741 [MEDIUM] CVE-2023-39741: lrzip v0 lrzip v0.651 was discovered to contain a heap overflow via the libzpaq::PostProcessor::write(int) function at /libzpaq/libzpaq.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.
osv
CVE-2022-28044CRITICALCVSS 9.8≥ 0, < 0.641-1+deb11u1≥ 0, < 0.650-12022-04-15
CVE-2022-28044 [CRITICAL] CVE-2022-28044: Irzip v0 Irzip v0.640 was discovered to contain a heap memory corruption via the component lrzip.c:initialise_control.
osv
CVE-2022-26291MEDIUMCVSS 5.5≥ 0, < 0.641-1+deb11u1≥ 0, < 0.650-12022-03-28
CVE-2022-26291 [MEDIUM] CVE-2022-26291: lrzip v0 lrzip v0.641 was discovered to contain a multiple concurrency use-after-free between the functions zpaq_decompress_buf() and clear_rulist(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted Irz file.
osv
CVE-2020-25467MEDIUMCVSS 5.5≥ 0, < 0.640-12021-06-10
CVE-2020-25467 [MEDIUM] CVE-2020-25467: A null pointer dereference was discovered lzo_decompress_buf in stream A null pointer dereference was discovered lzo_decompress_buf in stream.c in Irzip 0.621 which allows an attacker to cause a denial of service (DOS) via a crafted compressed file.
osv
CVE-2021-27345MEDIUMCVSS 5.5≥ 0, < 0.640-12021-06-10
CVE-2021-27345 [MEDIUM] CVE-2021-27345: A null pointer dereference was discovered in ucompthread in stream A null pointer dereference was discovered in ucompthread in stream.c in Irzip 0.631 which allows attackers to cause a denial of service (DOS) via a crafted compressed file.
osv
CVE-2021-27347MEDIUMCVSS 5.5≥ 0, < 0.640-12021-06-10
CVE-2021-27347 [MEDIUM] CVE-2021-27347: Use after free in lzma_decompress_buf function in stream Use after free in lzma_decompress_buf function in stream.c in Irzip 0.631 allows attackers to cause Denial of Service (DoS) via a crafted compressed file.
osv
CVE-2018-11496MEDIUMCVSS 6.5≥ 0, < 0.631+git180528-12018-05-26
CVE-2018-11496 [MEDIUM] CVE-2018-11496: In Long Range Zip (aka lrzip) 0 In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in read_stream in stream.c, because decompress_file in lrzip.c lacks certain size validation.
osv
CVE-2018-10685CRITICALCVSS 9.8≥ 0, < 0.631+git180517-12018-05-02
CVE-2018-10685 [CRITICAL] CVE-2018-10685: In Long Range Zip (aka lrzip) 0 In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the lzma_decompress_buf function of stream.c, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
osv
CVE-2018-9058MEDIUMCVSS 5.5≥ 0, < 0.631+git180517-12018-03-27
CVE-2018-9058 [MEDIUM] CVE-2018-9058: In Long Range Zip (aka lrzip) 0 In Long Range Zip (aka lrzip) 0.631, there is an infinite loop in the runzip_fd function of runzip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file.
osv
CVE-2018-5786MEDIUMCVSS 5.5≥ 0, < 0.641-1+deb11u1≥ 0, < 0.651-22018-01-19
CVE-2018-5786 [MEDIUM] CVE-2018-5786: In Long Range Zip (aka lrzip) 0 In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the get_fileinfo function (lrzip.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file.
osv
CVE-2018-5747MEDIUMCVSS 5.5≥ 0, < 0.631+git180517-12018-01-17
CVE-2018-5747 [MEDIUM] CVE-2018-5747: In Long Range Zip (aka lrzip) 0 In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the ucompthread function (stream.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file.
osv
CVE-2018-5650MEDIUMCVSS 5.5≥ 0, < 0.631+git180517-12018-01-12
CVE-2018-5650 [MEDIUM] CVE-2018-5650: In Long Range Zip (aka lrzip) 0 In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the unzip_match function in runzip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file.
osv
CVE-2017-9929MEDIUMCVSS 5.5≥ 0, < 0.631+git180517-12017-06-26
CVE-2017-9929 [MEDIUM] CVE-2017-9929: In lrzip 0 In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:1074, which allows attackers to cause a denial of service via a crafted file.
osv
CVE-2017-9928MEDIUMCVSS 5.5≥ 0, < 0.631+git180517-12017-06-26
CVE-2017-9928 [MEDIUM] CVE-2017-9928: In lrzip 0 In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:979, which allows attackers to cause a denial of service via a crafted file.
osv
CVE-2017-8844HIGHCVSS 7.8≥ 0, < 0.631+git180517-12017-05-08
CVE-2017-8844 [HIGH] CVE-2017-8844: The read_1g function in stream The read_1g function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted archive.
osv
CVE-2017-8843MEDIUMCVSS 5.5≥ 0, < 0.631+git180517-12017-05-08
CVE-2017-8843 [MEDIUM] CVE-2017-8843: The join_pthread function in stream The join_pthread function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive.
osv
CVE-2017-8847MEDIUMCVSS 5.5≥ 0, < 0.631+git180517-12017-05-08
CVE-2017-8847 [MEDIUM] CVE-2017-8847: The bufRead::get() function in libzpaq/libzpaq The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive.
osv