lrzsz before version 0.12.21~rc can leak information to the receiving side due to an incorrect length check in the function zsdata that causes a size_t to wrap around.
2021-06-02T14:15:07.817
2024-11-21T03:40:59.697
Modified
CVSSv3.1: 7.1 (HIGH)
AV:L/AC:L/Au:N/C:P/I:N/A:P
3.9
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | lrzsz_project | lrzsz | ≤ 0.12.20 | Yes |
Application | suse | linux_enterprise_debuginfo | 11 | Yes |
Operating System | suse | linux_enterprise_desktop | 12 | Yes |
Operating System | suse | linux_enterprise_server | 11 | Yes |
Operating System | suse | linux_enterprise_server | 12 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |