Debian Security Advisory

DLA-2725-1 lrzip -- LTS security update

Date Reported:
01 Aug 2021
Affected Packages:
lrzip
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2017-8844, CVE-2017-8846, CVE-2017-9928, CVE-2017-9929, CVE-2018-5650, CVE-2018-5747, CVE-2018-5786, CVE-2018-10685, CVE-2018-11496.
More information:

Several security vulnerabilities have been discovered in lrzip, a compression program. Heap-based and stack buffer overflows, use-after-free and infinite loops would allow attackers to cause a denial of service or possibly other unspecified impact via a crafted file.

For Debian 9 stretch, these problems have been fixed in version 0.631-1+deb9u1.

We recommend that you upgrade your lrzip packages.

For the detailed security status of lrzip please refer to its security tracker page at: https://security-tracker.debian.org/tracker/lrzip

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS