NA

CVE-2023-39741

Published: 17/08/2023 Updated: 25/08/2023
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

lrzip v0.651 exists to contain a heap overflow via the libzpaq::PostProcessor::write(int) function at /libzpaq/libzpaq.cpp. This vulnerability allows malicious users to cause a Denial of Service (DoS) via a crafted file.

Vulnerable Product Search on Vulmon Subscribe to Product

long range zip project long range zip 0.651

Vendor Advisories

Debian Bug report logs - #1059293 lrzip: CVE-2023-39741 Package: src:lrzip; Maintainer for src:lrzip is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Fri, 22 Dec 2023 12:42:01 UTC Severity: grave Tags: security, upstream Fixed in version lrzip/0651-3 Done: Laszlo ...