Long Range ZIP: Multiple vulnerabilities — GLSA 202005-01

Multiple vulnerabilities have been found in Long Range ZIP, the worst of which could result in a Denial of Service condition.

Affected packages

app-arch/lrzip on all architectures
Affected versions < 0.631_p20190619
Unaffected versions >= 0.631_p20190619

Background

Optimized for compressing large files

Description

Multiple vulnerabilities have been discovered in Long Range ZIP. Please review the CVE identifiers referenced below for details.

Impact

A remote attacker could entice a user to open a specially crafted archive file possibly resulting in a Denial of Service condition.

Workaround

There is no known workaround at this time.

Resolution

All Long Range ZIP users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=app-arch/lrzip-0.631_p20190619"
 

References

Release date
May 12, 2020

Latest revision
May 12, 2020: 1

Severity
low

Exploitable
local, remote

Bugzilla entries