CVE-2017-8845: Medium severity long range zip project vulnerability
Published May 8, 2017
·Updated
The lzo1xdecompress function in lzo1xd.ch in LZO 2.08, as used in lrzip 0.631, allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted archive.
Affected Software
1 affected component
Long Range Zip Project Long Range Zip=0.631
Remediation
Patch Available
Event History
May 8, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-8845?
CVE-2017-8845 has been classified as a denial of service vulnerability.
2
How do I fix CVE-2017-8845?
To mitigate CVE-2017-8845, consider updating lrzip to version 0.632 or later.
3
What type of attack does CVE-2017-8845 facilitate?
CVE-2017-8845 allows attackers to cause a denial of service through an invalid memory read.
4
Which software versions are affected by CVE-2017-8845?
CVE-2017-8845 specifically affects lrzip version 0.631 that utilizes LZO 2.08.
5
Can CVE-2017-8845 be exploited remotely?
Yes, CVE-2017-8845 can be exploited by remote attackers via crafted archives.