Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-8846

Опубликовано: 08 мая 2017
Источник: debian

Описание

The read_stream function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted archive.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
lrzipfixed0.631+git180517-1package
lrzipno-dsajessiepackage
lrzipno-dsawheezypackage

Примечания

  • https://github.com/ckolivas/lrzip/issues/71

  • https://blogs.gentoo.org/ago/2017/05/07/lrzip-use-after-free-in-read_stream-stream-c/

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 8 лет назад

The read_stream function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted archive.

CVSS3: 5.5
nvd
больше 8 лет назад

The read_stream function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted archive.

CVSS3: 5.5
github
больше 3 лет назад

The read_stream function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted archive.