Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-8847

Опубликовано: 08 мая 2017
Источник: debian
EPSS Низкий

Описание

The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
lrzipfixed0.631+git180517-1package

Примечания

  • https://github.com/ckolivas/lrzip/issues/67

  • https://blogs.gentoo.org/ago/2017/05/07/lrzip-null-pointer-dereference-in-bufreadget-libzpaq-h/

  • Crash in CLI tool, no security implications

EPSS

Процентиль: 40%
0.00184
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 8 лет назад

The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive.

CVSS3: 5.5
nvd
больше 8 лет назад

The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive.

CVSS3: 5.5
github
больше 3 лет назад

The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive.

EPSS

Процентиль: 40%
0.00184
Низкий