Search CVE reports
1 – 10 of 28 results
A security vulnerability has been detected in ckolivas lrzip up to 0.651. This vulnerability affects the function ucompthread of the file stream.c. Such manipulation leads to null pointer dereference. The attack can only...
1 affected package
lrzip
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| lrzip | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
A vulnerability was found in ckolivas lrzip up to 0.651. This impacts the function lzma_decompress_buf of the file stream.c. Performing a manipulation results in use after free. Attacking locally is a requirement. The exploit has...
1 affected package
lrzip
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| lrzip | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
A security flaw has been discovered in ckolivas lrzip up to 0.651. This impacts the function __GI_____strtol_l_internal of the file strtol_l.c. Performing manipulation results in null pointer dereference. The attack is only...
1 affected package
lrzip
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| lrzip | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
lrzip-next LZMA v23.01 was discovered to contain an access violation via the component /bz3_decode_block src/libbz3.c.
1 affected package
lrzip
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| lrzip | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
lrzip v0.651 was discovered to contain a heap overflow via the libzpaq::PostProcessor::write(int) function at /libzpaq/libzpaq.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.
1 affected package
lrzip
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| lrzip | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
An issue was discovered in lrzip version 0.641. There is a use-after-free in ucompthread() in stream.c:1538.
1 affected package
lrzip
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| lrzip | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
An issue was discovered in lrzip version 0.641. There are memory leaks in fill_buffer() in stream.c.
1 affected package
lrzip
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| lrzip | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Lrzip v0.651 was discovered to contain multiple invalid arithmetic shifts via the functions get_magic in lrzip.c and Predictor::init in libzpaq/libzpaq.cpp. These vulnerabilities allow attackers to cause a Denial of Service via...
2 affected packages
lrzip, zpaq
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| lrzip | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| zpaq | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Some fixes available 6 of 7
Irzip v0.640 was discovered to contain a heap memory corruption via the component lrzip.c:initialise_control.
1 affected package
lrzip
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| lrzip | — | Fixed | Fixed | Fixed |
Some fixes available 3 of 4
lrzip v0.641 was discovered to contain a multiple concurrency use-after-free between the functions zpaq_decompress_buf() and clear_rulist(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted Irz file.
1 affected package
lrzip
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| lrzip | — | Not affected | Fixed | Fixed |