First published: Fri Aug 25 2023(Updated: )
An issue discovered in XZ 5.2.5 allows attackers to cause a denial of service via decompression of crafted file. References: <a href="https://tukaani.org/xz/">https://tukaani.org/xz/</a> <a href="https://github.com/snappyJack/CVE-request-XZ-5.2.5-has-denial-of-service-vulnerability">https://github.com/snappyJack/CVE-request-XZ-5.2.5-has-denial-of-service-vulnerability</a>
Affected Software | Affected Version | How to fix |
---|---|---|
Tukaani XZ |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
REDHAT-BUG-2234987 is classified as a denial of service vulnerability in XZ 5.2.5.
Users of XZ 5.2.5 can experience denial of service when attempting to decompress crafted files.
To address REDHAT-BUG-2234987, users should update to a patched version of the XZ software as soon as it is available.
REDHAT-BUG-2234987 specifically affects the XZ version 5.2.5.
Currently, there are no known workarounds for REDHAT-BUG-2234987; users should avoid processing untrusted files.