ELA-597-1 lrzip security update

multiple vulnerabilities

2022-04-13
Packagelrzip
Version0.616-1+deb8u1
Related CVEs CVE-2017-8842 CVE-2017-8843 CVE-2017-8844 CVE-2017-8845 CVE-2017-8846 CVE-2017-8847 CVE-2017-9928 CVE-2017-9929 CVE-2018-5650 CVE-2018-5747 CVE-2018-5786 CVE-2018-9058 CVE-2018-10685 CVE-2018-11496 CVE-2020-25467 CVE-2021-27345 CVE-2021-27347 CVE-2022-26291


Several security vulnerabilities have been discovered in lrzip, a compression program. Heap-based and stack buffer overflows, use-after-free and infinite loops would allow attackers to cause a denial of service or possibly other unspecified impact via a crafted compressed file.



For Debian 8 jessie, these problems have been fixed in version 0.616-1+deb8u1.

We recommend that you upgrade your lrzip packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.