Debian Security Advisory
DLA-2725-1 lrzip -- LTS security update
- Date Reported:
- 01 Aug 2021
- Affected Packages:
- lrzip
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2017-8844, CVE-2017-8846, CVE-2017-9928, CVE-2017-9929, CVE-2018-5650, CVE-2018-5747, CVE-2018-5786, CVE-2018-10685, CVE-2018-11496.
- More information:
-
Several security vulnerabilities have been discovered in lrzip, a compression program. Heap-based and stack buffer overflows, use-after-free and infinite loops would allow attackers to cause a denial of service or possibly other unspecified impact via a crafted file.
For Debian 9 stretch, these problems have been fixed in version 0.631-1+deb9u1.
We recommend that you upgrade your lrzip packages.
For the detailed security status of lrzip please refer to its security tracker page at: https://security-tracker.debian.org/tracker/lrzip
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS