CVE-2017-9928: Buffer Overflow
Published Jun 26, 2017
·Updated
In lrzip 0.631, a stack buffer overflow was found in the function getfileinfo in lrzip.c:979, which allows attackers to cause a denial of service via a crafted file.
Affected Software
2 affected components
Long Range Zip Project Long Range Zip=0.631
Debian Debian Linux=9.0
Remediation
Patch Available
Event History
Jun 26, 2017
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9928?
CVE-2017-9928 has a medium severity rating due to its potential to cause denial of service.
2
How do I fix CVE-2017-9928?
To fix CVE-2017-9928, upgrade lrzip to version 0.631 or apply any available security patches provided by your distribution.
3
What is the impact of CVE-2017-9928?
The impact of CVE-2017-9928 includes a stack buffer overflow that can lead to a denial of service.
4
Which versions are affected by CVE-2017-9928?
CVE-2017-9928 affects lrzip version 0.631 and Debian GNU/Linux version 9.0.
5
Are there any workarounds for CVE-2017-9928?
Currently, the recommended workaround for CVE-2017-9928 is to avoid using the vulnerable software version until it can be updated.