cbcvebase.

Debian Lrzip vulnerabilities

22 known vulnerabilities affecting debian/lrzip.

Total CVEs
22
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM12LOW8

Vulnerabilities

Page 1 of 2
CVE-2022-28044P3CRITICALCVSS 9.8fixed in lrzip 0.650-1 (bookworm)2022
CVE-2022-28044 [CRITICAL] CVE-2022-28044: lrzip - Irzip v0.640 was discovered to contain a heap memory corruption via the componen... Irzip v0.640 was discovered to contain a heap memory corruption via the component lrzip.c:initialise_control. Scope: local bookworm: resolved (fixed in 0.650-1) bullseye: resolved (fixed in 0.641-1+deb11u1) forky: resolved (fixed in 0.650-1) sid: resolved (fixed in 0.650-1) trixie: resolved (fixed in 0.650-1)
debian
CVE-2025-15570P3MEDIUMCVSS 4.8fixed in lrzip 0.660-1 (forky)2025
CVE-2025-15570 [MEDIUM] CVE-2025-15570: lrzip - A vulnerability was found in ckolivas lrzip up to 0.651. This impacts the functi... A vulnerability was found in ckolivas lrzip up to 0.651. This impacts the function lzma_decompress_buf of the file stream.c. Performing a manipulation results in use after free. Attacking locally is a requirement. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet. Scope
debian
CVE-2018-10685P3LOWCVSS 9.8fixed in lrzip 0.631+git180517-1 (bookworm)2018
CVE-2018-10685 [CRITICAL] CVE-2018-10685: lrzip - In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the lzma_decom... In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the lzma_decompress_buf function of stream.c, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact. Scope: local bookworm: resolved (fixed in 0.631+git180517-1) bullseye: resolved (fixed in 0.631+git180517-1) forky: resolved (fixed
debian
CVE-2017-8844P4HIGHCVSS 7.8fixed in lrzip 0.631+git180517-1 (bookworm)2017
CVE-2017-8844 [HIGH] CVE-2017-8844: lrzip - The read_1g function in stream.c in liblrzip.so in lrzip 0.631 allows remote att... The read_1g function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted archive. Scope: local bookworm: resolved (fixed in 0.631+git180517-1) bullseye: resolved (fixed in 0.631+git180517-1) forky: resolved (fixed in 0.631
debian
CVE-2018-11496P4MEDIUMCVSS 6.5fixed in lrzip 0.631+git180528-1 (bookworm)2018
CVE-2018-11496 [MEDIUM] CVE-2018-11496: lrzip - In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in read_stream in... In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in read_stream in stream.c, because decompress_file in lrzip.c lacks certain size validation. Scope: local bookworm: resolved (fixed in 0.631+git180528-1) bullseye: resolved (fixed in 0.631+git180528-1) forky: resolved (fixed in 0.631+git180528-1) sid: resolved (fixed in 0.631+git180528-1) trixie: resolv
debian
CVE-2025-15571P4MEDIUMCVSS 4.8fixed in lrzip 0.660-1 (forky)2025
CVE-2025-15571 [MEDIUM] CVE-2025-15571: lrzip - A security vulnerability has been detected in ckolivas lrzip up to 0.651. This v... A security vulnerability has been detected in ckolivas lrzip up to 0.651. This vulnerability affects the function ucompthread of the file stream.c. Such manipulation leads to null pointer dereference. The attack can only be performed from a local environment. The exploit has been disclosed publicly and may be used. The project was informed of the problem early throu
debian
CVE-2018-5747P4MEDIUMCVSS 5.5fixed in lrzip 0.631+git180517-1 (bookworm)2018
CVE-2018-5747 [MEDIUM] CVE-2018-5747: lrzip - In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the ucompthrea... In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the ucompthread function (stream.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file. Scope: local bookworm: resolved (fixed in 0.631+git180517-1) bullseye: resolved (fixed in 0.631+git180517-1) forky: resolved (fixed in 0.631+git180517-1) sid: reso
debian
CVE-2022-26291P4MEDIUMCVSS 5.5fixed in lrzip 0.650-1 (bookworm)2022
CVE-2022-26291 [MEDIUM] CVE-2022-26291: lrzip - lrzip v0.641 was discovered to contain a multiple concurrency use-after-free bet... lrzip v0.641 was discovered to contain a multiple concurrency use-after-free between the functions zpaq_decompress_buf() and clear_rulist(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted Irz file. Scope: local bookworm: resolved (fixed in 0.650-1) bullseye: resolved (fixed in 0.641-1+deb11u1) forky: resolved (fixed in 0.650-1)
debian
CVE-2017-8846P4MEDIUMCVSS 5.5fixed in lrzip 0.631+git180517-1 (bookworm)2017
CVE-2017-8846 [MEDIUM] CVE-2017-8846: lrzip - The read_stream function in stream.c in liblrzip.so in lrzip 0.631 allows remote... The read_stream function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted archive. Scope: local bookworm: resolved (fixed in 0.631+git180517-1) bullseye: resolved (fixed in 0.631+git180517-1) forky: resolved (fixed in 0.631+git180517-1) sid: resolved (fixed in 0.631+git1
debian
CVE-2017-9929P4MEDIUMCVSS 5.5fixed in lrzip 0.631+git180517-1 (bookworm)2017
CVE-2017-9929 [MEDIUM] CVE-2017-9929: lrzip - In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo i... In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:1074, which allows attackers to cause a denial of service via a crafted file. Scope: local bookworm: resolved (fixed in 0.631+git180517-1) bullseye: resolved (fixed in 0.631+git180517-1) forky: resolved (fixed in 0.631+git180517-1) sid: resolved (fixed in 0.631+git180517-1) trixi
debian
CVE-2017-9928P4MEDIUMCVSS 5.5fixed in lrzip 0.631+git180517-1 (bookworm)2017
CVE-2017-9928 [MEDIUM] CVE-2017-9928: lrzip - In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo i... In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:979, which allows attackers to cause a denial of service via a crafted file. Scope: local bookworm: resolved (fixed in 0.631+git180517-1) bullseye: resolved (fixed in 0.631+git180517-1) forky: resolved (fixed in 0.631+git180517-1) sid: resolved (fixed in 0.631+git180517-1) trixie
debian
CVE-2021-27347P4LOWCVSS 5.5fixed in lrzip 0.640-1 (bookworm)2021
CVE-2021-27347 [MEDIUM] CVE-2021-27347: lrzip - Use after free in lzma_decompress_buf function in stream.c in Irzip 0.631 allows... Use after free in lzma_decompress_buf function in stream.c in Irzip 0.631 allows attackers to cause Denial of Service (DoS) via a crafted compressed file. Scope: local bookworm: resolved (fixed in 0.640-1) bullseye: resolved (fixed in 0.640-1) forky: resolved (fixed in 0.640-1) sid: resolved (fixed in 0.640-1) trixie: resolved (fixed in 0.640-1)
debian
CVE-2023-39741P4MEDIUMCVSS 5.5fixed in lrzip 0.651-3 (forky)2023
CVE-2023-39741 [MEDIUM] CVE-2023-39741: lrzip - lrzip v0.651 was discovered to contain a heap overflow via the libzpaq::PostProc... lrzip v0.651 was discovered to contain a heap overflow via the libzpaq::PostProcessor::write(int) function at /libzpaq/libzpaq.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 0.651-3) sid: resolved (fixed in 0.651-3) trixie: resolved (fixed in 0.651-3
debian
CVE-2017-8842P4LOWCVSS 5.5fixed in lrzip 0.631+git180517-1 (bookworm)2017
CVE-2017-8842 [MEDIUM] CVE-2017-8842: lrzip - The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 a... The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted archive. Scope: local bookworm: resolved (fixed in 0.631+git180517-1) bullseye: resolved (fixed in 0.631+git180517-1) forky: resolved (fixed in 0.631+git180517-1) sid: resolved (f
debian
CVE-2017-8847P4LOWCVSS 5.5fixed in lrzip 0.631+git180517-1 (bookworm)2017
CVE-2017-8847 [MEDIUM] CVE-2017-8847: lrzip - The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 a... The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive. Scope: local bookworm: resolved (fixed in 0.631+git180517-1) bullseye: resolved (fixed in 0.631+git180517-1) forky: resolved (fixed in 0.631+git180517-1) sid: resolve
debian
CVE-2017-8843P4LOWCVSS 5.5fixed in lrzip 0.631+git180517-1 (bookworm)2017
CVE-2017-8843 [MEDIUM] CVE-2017-8843: lrzip - The join_pthread function in stream.c in liblrzip.so in lrzip 0.631 allows remot... The join_pthread function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive. Scope: local bookworm: resolved (fixed in 0.631+git180517-1) bullseye: resolved (fixed in 0.631+git180517-1) forky: resolved (fixed in 0.631+git180517-1) sid: resolved (fixed in
debian
CVE-2018-5786P4MEDIUMCVSS 5.5fixed in lrzip 0.651-2 (bookworm)2018
CVE-2018-5786 [MEDIUM] CVE-2018-5786: lrzip - In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application h... In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the get_fileinfo function (lrzip.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file. Scope: local bookworm: resolved (fixed in 0.651-2) bullseye: resolved (fixed in 0.641-1+deb11u1) forky: resolved (fixed in 0.651-2) sid: resol
debian
CVE-2018-5650P4MEDIUMCVSS 5.5fixed in lrzip 0.631+git180517-1 (bookworm)2018
CVE-2018-5650 [MEDIUM] CVE-2018-5650: lrzip - In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application h... In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the unzip_match function in runzip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file. Scope: local bookworm: resolved (fixed in 0.631+git180517-1) bullseye: resolved (fixed in 0.631+git180517-1) forky: resolved (fixed in 0.631+
debian
CVE-2018-9058P4LOWCVSS 5.5fixed in lrzip 0.631+git180517-1 (bookworm)2018
CVE-2018-9058 [MEDIUM] CVE-2018-9058: lrzip - In Long Range Zip (aka lrzip) 0.631, there is an infinite loop in the runzip_fd ... In Long Range Zip (aka lrzip) 0.631, there is an infinite loop in the runzip_fd function of runzip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file. Scope: local bookworm: resolved (fixed in 0.631+git180517-1) bullseye: resolved (fixed in 0.631+git180517-1) forky: resolved (fixed in 0.631+git180517-1) sid: resol
debian
CVE-2017-8845P4LOWCVSS 5.5fixed in lrzip 0.631+git180517-1 (bookworm)2017
CVE-2017-8845 [MEDIUM] CVE-2017-8845: lrzip - The lzo1x_decompress function in lzo1x_d.ch in LZO 2.08, as used in lrzip 0.631,... The lzo1x_decompress function in lzo1x_d.ch in LZO 2.08, as used in lrzip 0.631, allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted archive. Scope: local bookworm: resolved (fixed in 0.631+git180517-1) bullseye: resolved (fixed in 0.631+git180517-1) forky: resolved (fixed in 0.631+git180517-1) sid: resolved (
debian
Debian Lrzip vulnerabilities | cvebase