Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-8842

Опубликовано: 08 мая 2017
Источник: debian

Описание

The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted archive.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
lrzipfixed0.631+git180517-1package

Примечания

  • https://github.com/ckolivas/lrzip/issues/66

  • https://blogs.gentoo.org/ago/2017/05/07/lrzip-divide-by-zero-in-bufreadget-libzpaq-h/

  • https://github.com/ckolivas/lrzip/commit/38386bd482c0a8102a79958cb3eddcb97a167ca3 (v0.640)

  • Crash in CLI tool, no security implications

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 8 лет назад

The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted archive.

CVSS3: 5.5
nvd
больше 8 лет назад

The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted archive.

CVSS3: 5.5
github
больше 3 лет назад

The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted archive.