First published: Tue Aug 22 2023(Updated: )
** DISPUTED ** An issue discovered in XZ 5.2.5 allows attackers to cause a denial of service via decompression of a crafted file. NOTE: the vendor disputes the claims of "endless output" and "denial of service" because decompression of the 17,486 bytes always results in 114,881,179 bytes, which is often a reasonable size increase.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tukaani XZ | =5.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-22916 is a vulnerability discovered in XZ version 5.2.5 that allows attackers to cause a denial of service by exploiting a crafted file during decompression.
The severity of CVE-2020-22916 is medium with a severity value of 5.5.
To fix CVE-2020-22916, update to a version of XZ that is not affected by this vulnerability, if available. Ensure you are using the latest version and follow any provided patches or updates from the vendor.
Yes, there is a dispute regarding CVE-2020-22916 as the vendor disputes the claims of "endless output" and "denial of service" associated with the vulnerability.
You can find more information about CVE-2020-22916 on the Debian Security Tracker page, the official Tukaani XZ website, and the GitHub repository that reported the vulnerability.