CVE-2018-5650: Medium severity Long Range Zip Project Long Range Zip vulnerability
In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the unzipmatch function in runzip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-5650?
CVE-2018-5650 is a vulnerability in Long Range Zip (lrzip) 0.631 that allows remote attackers to cause a denial of service through an infinite loop in the unzip_match function.
How severe is CVE-2018-5650?
CVE-2018-5650 has a severity score of 5.5, which is considered medium.
Which software versions are affected by CVE-2018-5650?
The affected software version is Long Range Zip (lrzip) 0.631.
How can I fix CVE-2018-5650?
To fix CVE-2018-5650, it is recommended to update Long Range Zip (lrzip) to a version that addresses the vulnerability.
Where can I find more information about CVE-2018-5650?
More information about CVE-2018-5650 can be found in the references: [GitHub issue](https://github.com/ckolivas/lrzip/issues/88) and [Debian LTS announcement](https://lists.debian.org/debian-lts-announce/2021/08/msg00001.html).