5.3 MEDIUM
- CVSS version: 3.1
- Attack vector (AV):
- Attack complexity (AC):
- Privileges required (PR):
- User interaction (UI):
- Scope (S):
- Confidentiality impact (C):
- Integrity impact (I):
- Availability impact (A):
Activity log
- Created suggestion
ckolivas lrzip stream.c lzma_decompress_buf use after free
A vulnerability was found in ckolivas lrzip up to 0.651. This impacts the function lzma_decompress_buf of the file stream.c. Performing a manipulation results in use after free. Attacking locally is a requirement. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
References
-
VDB-344926 | ckolivas lrzip stream.c lzma_decompress_buf use after free vdb-entrytechnical-description
-
-
Submit #752595 | ckolivas lrzip 0.651 Memory Corruption third-party-advisory
-
https://github.com/ckolivas/lrzip/issues/262 issue-tracking
Affected products
- ==0.651