Multiple vulnerabilities were found in lrzip. CVE-2017-8842 - The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip allows attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted archive. https://github.com/ckolivas/lrzip/issues/66 CVE-2017-8843 - The join_pthread function in stream.c in liblrzip.so in lrzip allows attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive. https://github.com/ckolivas/lrzip/issues/69 CVE-2017-8844 - The read_1g function in stream.c in liblrzip.so in lrzip allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted archive. https://github.com/ckolivas/lrzip/issues/70 CVE-2017-8845 - The lzo1x_decompress function in lzo1x_d.ch in LZO 2.08, as used in lrzip, allows attackers to cause a denial of service (invalid memory read and application crash) via a crafted archive. https://github.com/ckolivas/lrzip/issues/68 CVE-2017-8846 - The read_stream function in stream.c in liblrzip.so in lrzip allows attackers to cause a denial of service (use-after-free and application crash) via a crafted archive. https://github.com/ckolivas/lrzip/issues/71 CVE-2017-8847 - The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip allows attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive. https://github.com/ckolivas/lrzip/issues/67
Created lrzip tracking bugs for this issue: Affects: epel-all [bug 1449179] Affects: fedora-all [bug 1449180]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.