CVE-2022-28044: Critical severity irzip vulnerability
Published Apr 15, 2022
·Updated
Irzip v0.640 was discovered to contain a heap memory corruption via the component lrzip.c:initialisecontrol.
Affected Software
5 affected componentsFixes available
debian/lrzip
0.631+git180528-1+deb10u10.641-1+deb11u10.651-2
Irzip Project Irzip=0.640
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Remediation
Patch Available
Event History
Apr 15, 2022
CVE Published
via MITRE·01:06 PM
Data Sourced
via MITRE·01:06 PM
Description
Frequently Asked Questions
1
What is CVE-2022-28044?
CVE-2022-28044 is a vulnerability in Irzip v0.640 that allows heap memory corruption via the component lrzip.c:initialise_control.
2
How does CVE-2022-28044 affect lrzip?
CVE-2022-28044 affects lrzip v0.640.
3
What is the severity of CVE-2022-28044?
The severity of CVE-2022-28044 is critical with a CVSS score of 9.8.
4
How can I fix CVE-2022-28044?
To fix CVE-2022-28044, update lrzip to version 0.641-1+deb11u1 or higher.
5
Where can I find more information about CVE-2022-28044?
You can find more information about CVE-2022-28044 in the following references: [link1](https://github.com/ckolivas/lrzip/commit/5faf80cd53ecfd16b636d653483144cd12004f46), [link2](https://github.com/ckolivas/lrzip/issues/216), [link3](https://lists.debian.org/debian-lts-announce/2022/05/msg00016.html).