Bug ID 1131254
Summary VUL-0: CVE-2019-10654: lrzip: Invalid memory read and application crash via crafted file
Classification openSUSE
Product openSUSE Distribution
Version Leap 42.3
Hardware Other
URL https://smash.suse.de/issue/228521/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee mpluskal@suse.com
Reporter atoptsoglou@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

The lzo1x_decompress function in liblzo2.so.2 in LZO 2.10, as used in Long
Range Zip (aka lrzip) 0.631, allows remote attackers to cause a denial of
service (invalid memory read and application crash) via a crafted archive, a
different vulnerability than CVE-2017-8845.

Upstream issue:

https://github.com/ckolivas/lrzip/issues/108

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1694847
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-10654
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10654
https://github.com/ckolivas/lrzip/issues/108


You are receiving this mail because: