ELA-552-1 lrzsz security update

possible data leak

2022-01-25
Packagelrzsz
Version0.12.21-7+deb8u1
Related CVEs CVE-2018-10195


An issues has been found in lrzsz, a set of tools for zmodem/xmodem/ymodem file transfer. Due to an incorrect length check, which might result in a size_t wrap around, an information leak to the receiving side could happen.



For Debian 8 jessie, these problems have been fixed in version 0.12.21-7+deb8u1.

We recommend that you upgrade your lrzsz packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.