Your submission was sent successfully! Close

Thank you for contacting us. A member of our team will be in touch shortly. Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

11 – 20 of 25 results


CVE-2019-10654

Low priority
Vulnerable

The lzo1x_decompress function in liblzo2.so.2 in LZO 2.10, as used in Long Range Zip (aka lrzip) 0.631, allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted archive, a...

1 affected packages

lrzip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
lrzip Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2018-11496

Medium priority

Some fixes available 3 of 4

In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in read_stream in stream.c, because decompress_file in lrzip.c lacks certain size validation.

1 affected packages

lrzip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
lrzip Not affected Not affected Fixed Fixed
Show less packages

CVE-2018-10685

Medium priority

Some fixes available 3 of 4

In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the lzma_decompress_buf function of stream.c, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

1 affected packages

lrzip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
lrzip Not affected Not affected Fixed Fixed
Show less packages

CVE-2018-9058

Medium priority

Some fixes available 3 of 4

In Long Range Zip (aka lrzip) 0.631, there is an infinite loop in the runzip_fd function of runzip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file.

1 affected packages

lrzip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
lrzip Not affected Not affected Fixed Fixed
Show less packages

CVE-2018-5786

Medium priority

Some fixes available 3 of 4

In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the get_fileinfo function (lrzip.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file.

1 affected packages

lrzip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
lrzip Not affected Not affected Fixed Fixed
Show less packages

CVE-2018-5747

Medium priority

Some fixes available 3 of 4

In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the ucompthread function (stream.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file.

1 affected packages

lrzip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
lrzip Not affected Not affected Fixed Fixed
Show less packages

CVE-2018-5650

Medium priority

Some fixes available 3 of 4

In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the unzip_match function in runzip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file.

1 affected packages

lrzip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
lrzip Not affected Not affected Fixed Fixed
Show less packages

CVE-2017-9929

Medium priority

Some fixes available 3 of 6

In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:1074, which allows attackers to cause a denial of service via a crafted file.

1 affected packages

lrzip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
lrzip Not affected Not affected Fixed Fixed
Show less packages

CVE-2017-9928

Medium priority

Some fixes available 3 of 6

In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:979, which allows attackers to cause a denial of service via a crafted file.

1 affected packages

lrzip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
lrzip Not affected Not affected Fixed Fixed
Show less packages

CVE-2017-8847

Low priority

Some fixes available 1 of 6

The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive.

1 affected packages

lrzip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
lrzip Not affected Not affected Not affected Fixed Vulnerable
Show less packages