CVE-2021-27345: Null Pointer Dereference
Published Jun 10, 2021
·Updated
A null pointer dereference was discovered in ucompthread in stream.c in Irzip 0.631 which allows attackers to cause a denial of service (DOS) via a crafted compressed file.
Affected Software
2 affected components
Long Range Zip Project Long Range Zip=0.631
Debian Debian Linux=9.0
Remediation
Patch Available
Event History
Jun 10, 2021
CVE Published
via MITRE·03:45 PM
Data Sourced
via MITRE·03:45 PM
Description
Frequently Asked Questions
1
What is CVE-2021-27345?
CVE-2021-27345 is a null pointer dereference vulnerability in ucompthread in Irzip 0.631.
2
How does CVE-2021-27345 impact systems?
CVE-2021-27345 allows attackers to cause a denial of service (DOS) by exploiting a null pointer dereference in Irzip 0.631.
3
Which software versions are affected by CVE-2021-27345?
Irzip 0.631 and Debian Linux 9.0 are affected by CVE-2021-27345.
4
What is the severity rating of CVE-2021-27345?
CVE-2021-27345 has a severity rating of medium (5.5) according to the Common Vulnerability Scoring System (CVSS) v3.1.
5
How can I fix CVE-2021-27345?
Update Irzip to a patched version, such as version 0.632, to fix CVE-2021-27345.