CVE-2017-9928

NameCVE-2017-9928
DescriptionIn lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:979, which allows attackers to cause a denial of service via a crafted file.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium (attack range: remote)
Debian Bugs866022

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
lrzip (PTS)wheezy0.608-2vulnerable
jessie0.616-1vulnerable
buster, sid, stretch0.631-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
lrzipsource(unstable)(unfixed)medium866022

Notes

[stretch] - lrzip <no-dsa> (Minor issue)
[jessie] - lrzip <no-dsa> (Minor issue)
[wheezy] - lrzip <no-dsa> (Minor issue)
https://github.com/ckolivas/lrzip/issues/74

Search for package or bug name: Reporting problems