CVE-2018-5786: Medium severity Long Range Zip Project Long Range Zip vulnerability
In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the getfileinfo function (lrzip.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/lrzipto a version that resolves this vulnerability.Fixed in 0.631+git180528-1+deb10u1Fixed in 0.641-1+deb11u1Fixed in 0.651-2
Event History
Frequently Asked Questions
What is the severity of CVE-2018-5786?
The severity of CVE-2018-5786 is medium with a severity value of 5.5.
How can remote attackers exploit CVE-2018-5786?
Remote attackers can exploit CVE-2018-5786 to cause a denial of service by leveraging the infinite loop vulnerability in the get_fileinfo function of lrzip.
Which software versions are affected by CVE-2018-5786?
lrzip version 0.631 is affected by CVE-2018-5786, as well as Debian Linux versions 9.0, 10.0, and 11.0.
How can I fix CVE-2018-5786?
To fix CVE-2018-5786, update lrzip to versions 0.631+git180528-1+deb10u1, 0.641-1+deb11u1, or 0.651-2, depending on your Debian Linux version.
Where can I find more information about CVE-2018-5786?
You can find more information about CVE-2018-5786 at the following references: [1](https://github.com/ckolivas/lrzip/issues/91), [2](https://github.com/ckolivas/lrzip/commit/3495188cd8f2215a9feea201f3e05c1341ed95fb), [3](https://security-tracker.debian.org/tracker/CVE-2018-5786).