Long Range Zip Project Long Range Zip vulnerabilities
23 known vulnerabilities affecting long_range_zip_project/long_range_zip.
Total CVEs
23
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM20
Vulnerabilities
Page 1 of 2
CVE-2023-39741MEDIUMCVSS 5.5v0.6512023-08-17
CVE-2023-39741 [MEDIUM] CWE-787 CVE-2023-39741: lrzip v0.651 was discovered to contain a heap overflow via the libzpaq::PostProcessor::write(int) fu
lrzip v0.651 was discovered to contain a heap overflow via the libzpaq::PostProcessor::write(int) function at /libzpaq/libzpaq.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.
nvd
CVE-2021-33453HIGHCVSS 7.8v0.6412022-07-26
CVE-2021-33453 [HIGH] CWE-416 CVE-2021-33453: An issue was discovered in lrzip version 0.641. There is a use-after-free in ucompthread() in stream
An issue was discovered in lrzip version 0.641. There is a use-after-free in ucompthread() in stream.c:1538.
nvd
CVE-2021-33451MEDIUMCVSS 5.5v0.6412022-07-26
CVE-2021-33451 [MEDIUM] CWE-401 CVE-2021-33451: An issue was discovered in lrzip version 0.641. There are memory leaks in fill_buffer() in stream.c.
An issue was discovered in lrzip version 0.641. There are memory leaks in fill_buffer() in stream.c.
nvd
CVE-2022-33067MEDIUMCVSS 5.5v0.6512022-06-23
CVE-2022-33067 [MEDIUM] CVE-2022-33067: Lrzip v0.651 was discovered to contain multiple invalid arithmetic shifts via the functions get_magi
Lrzip v0.651 was discovered to contain multiple invalid arithmetic shifts via the functions get_magic in lrzip.c and Predictor::init in libzpaq/libzpaq.cpp. These vulnerabilities allow attackers to cause a Denial of Service via unspecified vectors.
nvd
CVE-2022-26291MEDIUMCVSS 5.5v0.6412022-03-28
CVE-2022-26291 [MEDIUM] CWE-416 CVE-2022-26291: lrzip v0.641 was discovered to contain a multiple concurrency use-after-free between the functions z
lrzip v0.641 was discovered to contain a multiple concurrency use-after-free between the functions zpaq_decompress_buf() and clear_rulist(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted Irz file.
nvd
CVE-2021-27347MEDIUMCVSS 5.5v0.6312021-06-10
CVE-2021-27347 [MEDIUM] CWE-416 CVE-2021-27347: Use after free in lzma_decompress_buf function in stream.c in Irzip 0.631 allows attackers to cause
Use after free in lzma_decompress_buf function in stream.c in Irzip 0.631 allows attackers to cause Denial of Service (DoS) via a crafted compressed file.
nvd
CVE-2021-27345MEDIUMCVSS 5.5v0.6312021-06-10
CVE-2021-27345 [MEDIUM] CWE-476 CVE-2021-27345: A null pointer dereference was discovered in ucompthread in stream.c in Irzip 0.631 which allows att
A null pointer dereference was discovered in ucompthread in stream.c in Irzip 0.631 which allows attackers to cause a denial of service (DOS) via a crafted compressed file.
nvd
CVE-2020-25467MEDIUMCVSS 5.5v0.6212021-06-10
CVE-2020-25467 [MEDIUM] CWE-476 CVE-2020-25467: A null pointer dereference was discovered lzo_decompress_buf in stream.c in Irzip 0.621 which allows
A null pointer dereference was discovered lzo_decompress_buf in stream.c in Irzip 0.621 which allows an attacker to cause a denial of service (DOS) via a crafted compressed file.
nvd
CVE-2019-10654MEDIUMCVSS 5.5v0.6312019-03-30
CVE-2019-10654 [MEDIUM] CVE-2019-10654: The lzo1x_decompress function in liblzo2.so.2 in LZO 2.10, as used in Long Range Zip (aka lrzip) 0.6
The lzo1x_decompress function in liblzo2.so.2 in LZO 2.10, as used in Long Range Zip (aka lrzip) 0.631, allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted archive, a different vulnerability than CVE-2017-8845.
nvd
CVE-2018-11496MEDIUMCVSS 6.5v0.6312018-05-26
CVE-2018-11496 [MEDIUM] CWE-416 CVE-2018-11496: In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in read_stream in stream.c, because d
In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in read_stream in stream.c, because decompress_file in lrzip.c lacks certain size validation.
nvd
CVE-2018-10685CRITICALCVSS 9.8v0.6312018-05-02
CVE-2018-10685 [CRITICAL] CWE-416 CVE-2018-10685: In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the lzma_decompress_buf function o
In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the lzma_decompress_buf function of stream.c, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
nvd
CVE-2018-9058MEDIUMCVSS 5.5v0.6312018-03-27
CVE-2018-9058 [MEDIUM] CWE-835 CVE-2018-9058: In Long Range Zip (aka lrzip) 0.631, there is an infinite loop in the runzip_fd function of runzip.c
In Long Range Zip (aka lrzip) 0.631, there is an infinite loop in the runzip_fd function of runzip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file.
nvd
CVE-2018-5786MEDIUMCVSS 5.5v0.6312018-01-19
CVE-2018-5786 [MEDIUM] CWE-835 CVE-2018-5786: In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the get_filei
In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the get_fileinfo function (lrzip.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file.
nvd
CVE-2018-5747MEDIUMCVSS 5.5v0.6312018-01-17
CVE-2018-5747 [MEDIUM] CWE-416 CVE-2018-5747: In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the ucompthread function (stream.c
In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the ucompthread function (stream.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file.
nvd
CVE-2018-5650MEDIUMCVSS 5.5v0.6312018-01-12
CVE-2018-5650 [MEDIUM] CWE-835 CVE-2018-5650: In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the unzip_mat
In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the unzip_match function in runzip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file.
nvd
CVE-2017-9929MEDIUMCVSS 5.5v0.6312017-06-26
CVE-2017-9929 [MEDIUM] CWE-119 CVE-2017-9929: In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:1074, whic
In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:1074, which allows attackers to cause a denial of service via a crafted file.
nvd
CVE-2017-9928MEDIUMCVSS 5.5v0.6312017-06-26
CVE-2017-9928 [MEDIUM] CWE-119 CVE-2017-9928: In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:979, which
In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:979, which allows attackers to cause a denial of service via a crafted file.
nvd
CVE-2017-8844HIGHCVSS 7.8v0.6312017-05-08
CVE-2017-8844 [HIGH] CWE-119 CVE-2017-8844: The read_1g function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a de
The read_1g function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted archive.
nvd
CVE-2017-8843MEDIUMCVSS 5.5v0.6312017-05-08
CVE-2017-8843 [MEDIUM] CWE-476 CVE-2017-8843: The join_pthread function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause
The join_pthread function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive.
nvd
CVE-2017-8842MEDIUMCVSS 5.5v0.6312017-05-08
CVE-2017-8842 [MEDIUM] CWE-369 CVE-2017-8842: The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attacke
The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted archive.
nvd
1 / 2Next →