Back

HIGH

lrzsz: Integer overflow in src/zm.c:zsdata() causes crash in sz and can leak information to receiver

Published Jun 2, 2021

Description

lrzsz before version 0.12.21~rc can leak information to the receiving side due to an incorrect length check in the function zsdata that causes a size_t to wrap around.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of lrzsz as shipped with Red Hat Enterprise Linux 5, 6, and 7. A patch was already applied for this vulnerability.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 2, 2021
Updated Aug 5, 2024
Reserved Apr 18, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Apr 18, 2018