CVE-2018-10685: Use After Free
Published May 2, 2018
·Updated
In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the lzmadecompressbuf function of stream.c, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
Affected Software
1 affected component
Long Range Zip Project Long Range Zip=0.631
Event History
May 2, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2018-10685.
2
What is the severity of CVE-2018-10685?
The severity of CVE-2018-10685 is critical with a CVSS score of 9.8.
3
What is the affected software?
The affected software is Long Range Zip (lrzip) version 0.631.
4
What is the impact of this vulnerability?
This vulnerability can cause a denial of service (application crash) or possibly have unspecified other impact.
5
How can I fix CVE-2018-10685?
To fix CVE-2018-10685, it is recommended to upgrade to a version of Long Range Zip (lrzip) that is not affected by this vulnerability.