Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-8845

Опубликовано: 08 мая 2017
Источник: debian
EPSS Низкий

Описание

The lzo1x_decompress function in lzo1x_d.ch in LZO 2.08, as used in lrzip 0.631, allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted archive.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
lrzipfixed0.631+git180517-1package

Примечания

  • https://github.com/ckolivas/lrzip/issues/68

  • https://github.com/ckolivas/lrzip/commit/89d7b33e6a6450eed326b40084b547d42bad333f

  • https://blogs.gentoo.org/ago/2017/05/07/lrzip-invalid-memory-read-in-lzo_decompress_buf-stream-c/

  • Crash in CLI tool, no security implications

EPSS

Процентиль: 40%
0.00184
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 8 лет назад

The lzo1x_decompress function in lzo1x_d.ch in LZO 2.08, as used in lrzip 0.631, allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted archive.

CVSS3: 5.5
nvd
больше 8 лет назад

The lzo1x_decompress function in lzo1x_d.ch in LZO 2.08, as used in lrzip 0.631, allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted archive.

CVSS3: 5.5
github
больше 3 лет назад

The lzo1x_decompress function in lzo1x_d.ch in LZO 2.08, as used in lrzip 0.631, allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted archive.

EPSS

Процентиль: 40%
0.00184
Низкий