See how long range zip project compares to other vendors in security performance
lrzip v0.651 was discovered to contain a heap overflow via the libzpaq::PostProcessor::write(int) function at /libzpaq/libzpaq.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.
An issue was discovered in lrzip version 0.641. There is a use-after-free in ucompthread() in stream.c:1538.
An issue was discovered in lrzip version 0.641. There are memory leaks in fillbuffer() in stream.c.
Lrzip v0.651 was discovered to contain multiple invalid arithmetic shifts via the functions getmagic in lrzip.c and Predictor::init in libzpaq/libzpaq.cpp. These vulnerabilities allow attackers to cause a Denial of Service via unspecified vectors.
lrzip v0.641 was discovered to contain a multiple concurrency use-after-free between the functions zpaqdecompressbuf() and clearrulist(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted Irz file.
A null pointer dereference was discovered in ucompthread in stream.c in Irzip 0.631 which allows attackers to cause a denial of service (DOS) via a crafted compressed file.
A null pointer dereference was discovered lzodecompressbuf in stream.c in Irzip 0.621 which allows an attacker to cause a denial of service (DOS) via a crafted compressed file.
Use after free in lzmadecompressbuf function in stream.c in Irzip 0.631 allows attackers to cause Denial of Service (DoS) via a crafted compressed file.
The lzo1xdecompress function in liblzo2.so.2 in LZO 2.10, as used in Long Range Zip (aka lrzip) 0.631, allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted archive, a different vulnerability than CVE-2017-8845.
In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in readstream in stream.c, because decompressfile in lrzip.c lacks certain size validation.
In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the lzmadecompressbuf function of stream.c, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
In Long Range Zip (aka lrzip) 0.631, there is an infinite loop in the runzipfd function of runzip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file.
In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the getfileinfo function (lrzip.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file.
In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the ucompthread function (stream.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file.
In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the unzipmatch function in runzip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file.
In lrzip 0.631, a stack buffer overflow was found in the function getfileinfo in lrzip.c:1074, which allows attackers to cause a denial of service via a crafted file.
In lrzip 0.631, a stack buffer overflow was found in the function getfileinfo in lrzip.c:979, which allows attackers to cause a denial of service via a crafted file.
The joinpthread function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive.
The read1g function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted archive.
The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive.
The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted archive.
The readstream function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted archive.
The lzo1xdecompress function in lzo1xd.ch in LZO 2.08, as used in lrzip 0.631, allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted archive.