Use-after-free in lrzip - CVE-2021-27347
Published: May 25, 2022 / Updated: May 25, 2022
Vulnerability identifier: #VU63644
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-27347
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to a use-after-free error in lzma_decompress_buf function in stream.c. A remote attacker can trick the victim to open a specially crafted compressed file and trigger denial of service conditions.
Affected software
lrzip
Ubuntu
lrzip (Ubuntu package)
lrzip (Debian package)
Ubuntu
lrzip (Ubuntu package)
lrzip (Debian package)
How to mitigate CVE-2021-27347
Install updates from vendor's website.
lrzip - update to 0.640
lrzip (Ubuntu package) - addressed in versions Ubuntu Pro, 0.631+git180528-1+deb10u1build0.20.04.1, 0.631-1+deb9u3build0.18.04.1, 0.651-2ubuntu0.22.04.1, 0.651-2ubuntu0.22.10.1
lrzip (Debian package) - addressed in versions 0.631+git180528-1+deb10u1, 0.641-1+deb11u1
lrzip (Ubuntu package) - addressed in versions Ubuntu Pro, 0.631+git180528-1+deb10u1build0.20.04.1, 0.631-1+deb9u3build0.18.04.1, 0.651-2ubuntu0.22.04.1, 0.651-2ubuntu0.22.10.1
lrzip (Debian package) - addressed in versions 0.631+git180528-1+deb10u1, 0.641-1+deb11u1