lrzip v0.651 was discovered to contain a heap overflow via the libzpaq::PostProcessor::write(int) function at /libzpaq/libzpaq.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.
{ "binaries": [ { "binary_name": "lrzip", "binary_version": "0.631+git180528-1+deb10u1build0.20.04.1" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-39741.json"
{ "binaries": [ { "binary_name": "lrzip", "binary_version": "0.651-2ubuntu0.22.04.1" } ] }
{ "binaries": [ { "binary_name": "lrzip", "binary_version": "0.651-2ubuntu1" } ] }
{ "binaries": [ { "binary_name": "lrzip", "binary_version": "0.651-3" } ] }
{ "binaries": [ { "binary_name": "lrzip", "binary_version": "0.616-1ubuntu0.1~esm2" } ] }
{ "binaries": [ { "binary_name": "lrzip", "binary_version": "0.621-1ubuntu0.1~esm2" } ] }
{ "binaries": [ { "binary_name": "lrzip", "binary_version": "0.631-1+deb9u3build0.18.04.1" } ] }