CVE-2021-27347: Use After Free
Use after free in lzmadecompressbuf function in stream.c in Irzip 0.631 allows attackers to cause Denial of Service (DoS) via a crafted compressed file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-27347?
CVE-2021-27347 refers to a vulnerability in the Irzip software that allows attackers to cause a Denial of Service (DoS) by exploiting a use after free vulnerability in the lzma_decompress_buf function in stream.c.
How does CVE-2021-27347 affect the Long Range Zip Project's Long Range Zip software?
The CVE-2021-27347 vulnerability affects Long Range Zip Project's Long Range Zip software version 0.631, potentially allowing attackers to cause a DoS attack using a crafted compressed file.
Which Debian Linux version is affected by CVE-2021-27347?
CVE-2021-27347 affects Debian Linux version 9.0.
What is the severity of CVE-2021-27347?
The severity of CVE-2021-27347 is rated as medium with a CVSS score of 5.5.
How can I fix CVE-2021-27347?
To fix CVE-2021-27347, it is recommended to update to a patched version of the Irzip software released by the Long Range Zip Project or to update the Debian Linux operating system to a version that includes the fix.