320
VMScore

CVE-2018-10195

Published: 02/06/2021 Updated: 21/02/2022
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.1 | Impact Score: 5.2 | Exploitability Score: 1.8
VMScore: 320
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

lrzsz before version 0.12.21~rc can leak information to the receiving side due to an incorrect length check in the function zsdata that causes a size_t to wrap around.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lrzsz project lrzsz

suse linux enterprise debuginfo 11

suse linux enterprise desktop 12

suse linux enterprise server 11

suse linux enterprise server 12

debian debian linux 9.0

Vendor Advisories

Debian Bug report logs - #897010 lrzsz: CVE-2018-10195: rzsz: sz can leak data to receiving side Package: src:lrzsz; Maintainer for src:lrzsz is Martin A Godisch <godisch@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 27 Apr 2018 04:21:02 UTC Severity: grave Tags: security, upstream F ...
lrzsz before version 01221~rc can leak information to the receiving side due to an incorrect length check in the function zsdata that causes a size_t to wrap around ...