CVE-2022-33067: Medium severity long range zip project vulnerability
Lrzip v0.651 was discovered to contain multiple invalid arithmetic shifts via the functions getmagic in lrzip.c and Predictor::init in libzpaq/libzpaq.cpp. These vulnerabilities allow attackers to cause a Denial of Service via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-33067?
CVE-2022-33067 is a vulnerability in Lrzip v0.651 that allows attackers to cause a Denial of Service via unspecified vectors.
How severe is CVE-2022-33067?
CVE-2022-33067 has a severity rating of medium with a score of 5.5.
Which software version is affected by CVE-2022-33067?
Lrzip v0.651 is affected by CVE-2022-33067.
How can attackers exploit CVE-2022-33067?
Attackers can exploit CVE-2022-33067 to cause a Denial of Service by exploiting invalid arithmetic shifts in the get_magic function in lrzip.c and the init function in libzpaq/libzpaq.cpp.
Is there a fix available for CVE-2022-33067?
At the moment, there is no known fix available for CVE-2022-33067. It is recommended to update to a newer version once a fix is released.