Division by zero in lrzip - CVE-2017-8842
Published: May 8, 2017 / Updated: February 16, 2021
lrzip
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to divide-by-zero error within The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631. A remote attacker can perform a denial of service (divide-by-zero error and application crash) via a crafted archive.