Bug ID 1091757
Summary VUL-0: CVE-2018-10685: lrzip: There is a use-after-free in the lzma_decompress_buf function of stream.c, which allows remote attackers to cause a denial of service (application crash)
Classification openSUSE
Product openSUSE Distribution
Version Leap 42.3
Hardware Other
URL https://smash.suse.de/issue/205219/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee mpluskal@suse.com
Reporter kbabioch@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

CVE-2018-10685

In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the
lzma_decompress_buf function of stream.c, which allows remote attackers to
cause
a denial of service (application crash) or possibly have unspecified other
impact.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-10685
https://github.com/ckolivas/lrzip/issues/95


You are receiving this mail because: