Candidate: CVE-2017-8845 PublicDate: 2017-05-08 14:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8845 https://blogs.gentoo.org/ago/2017/05/07/lrzip-invalid-memory-read-in-lzo_decompress_buf-stream-c/ Description: The lzo1x_decompress function in lzo1x_d.ch in LZO 2.08, as used in lrzip 0.631, allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted archive. Ubuntu-Description: Notes: Bugs: https://github.com/ckolivas/lrzip/issues/68 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=863151 Priority: low Discovered-by: Agostino Sarubbo Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [5.5 MEDIUM] Patches_lrzip: upstream: https://github.com/ckolivas/lrzip/commit/89d7b33e6a6450eed326b40084b547d42bad333f upstream_lrzip: released (0.631+git180517-1) precise/esm_lrzip: DNE trusty_lrzip: ignored (reached end-of-life) trusty/esm_lrzip: DNE xenial_lrzip: ignored (end of standard support, was needed) yakkety_lrzip: ignored (reached end-of-life) zesty_lrzip: ignored (reached end-of-life) artful_lrzip: ignored (reached end-of-life) bionic_lrzip: needed cosmic_lrzip: ignored (reached end-of-life) disco_lrzip: ignored (reached end-of-life) eoan_lrzip: ignored (reached end-of-life) focal_lrzip: not-affected (0.631+git180528-1build1) groovy_lrzip: not-affected (0.631+git200516-1) hirsute_lrzip: not-affected (0.631+git200516-1) impish_lrzip: not-affected (0.631+git200516-1) jammy_lrzip: not-affected (0.631+git200516-1) devel_lrzip: not-affected (0.631+git200516-1)