Description
The lzo1x_decompress function in liblzo2.so.2 in LZO 2.10, as used in Long Range Zip (aka lrzip) 0.631, allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted archive, a different vulnerability than CVE-2017-8845.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-2454 | The lzo1x_decompress function in liblzo2.so.2 in LZO 2.10, as used in Long Range Zip (aka lrzip) 0.631, allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted archive, a different vulnerability than CVE-2017-8845. |
References
| Link | Providers |
|---|---|
| https://github.com/ckolivas/lrzip/issues/108 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T22:32:00.663Z
Reserved: 2019-03-30T00:00:00.000Z
Link: CVE-2019-10654
No data.
Status : Modified
Published: 2019-03-30T15:29:00.207
Modified: 2024-11-21T04:19:40.970
Link: CVE-2019-10654
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD