A null pointer dereference was discovered lzo_decompress_buf in stream.c in Irzip 0.621 which allows an attacker to cause a denial of service (DOS) via a crafted compressed file.
References
Link Resource
https://bugs.launchpad.net/ubuntu/+source/lrzip/+bug/1893641 Exploit Issue Tracking Third Party Advisory
https://github.com/ckolivas/lrzip/issues/163 Exploit Issue Tracking Patch Third Party Advisory
https://lists.debian.org/debian-lts-announce/2022/04/msg00012.html Mailing List Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-06-10T15:41:29

Updated: 2022-04-13T15:06:15

Reserved: 2020-09-14T00:00:00


Link: CVE-2020-25467

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-06-10T16:15:07.827

Modified: 2022-04-27T17:19:28.813


Link: CVE-2020-25467

JSON object: View

cve-icon Redhat Information

No data.

CWE