CVE-2017-8846: Use After Free
Published May 8, 2017
·Updated
The readstream function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted archive.
Affected Software
2 affected components
Long Range Zip Project Long Range Zip=0.631
Debian Debian Linux=9.0
Remediation
Patch Available
Event History
May 8, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-8846?
CVE-2017-8846 has a high severity rating due to its potential to cause denial of service through use-after-free vulnerabilities.
2
How do I fix CVE-2017-8846?
To fix CVE-2017-8846, you should update your lrzip software to version 0.632 or later.
3
What is the impact of CVE-2017-8846?
The impact of CVE-2017-8846 is a denial of service condition, which can crash the application when processing a crafted archive.
4
Which software versions are affected by CVE-2017-8846?
CVE-2017-8846 affects lrzip version 0.631 and Debian GNU/Linux 9.0.
5
Who is vulnerable to CVE-2017-8846?
Users of lrzip version 0.631 and Debian 9.0 are vulnerable to CVE-2017-8846 if they process untrusted archive files.