lrzsz before version 0.12.21~rc can leak information to the receiving side
due to an incorrect length check in the function zsdata that causes a
size_t to wrap around. (CVE-2018-10195)
- https://bugs.mageia.org/show_bug.cgi?id=29970
- https://lists.debian.org/debian-lts-announce/2022/01/msg00027.html
- https://www.cve.org/CVERecord?id=CVE-2018-10195
- 8/core/lrzsz-0.12.21-23.1.mga8
Get the latest Linux and open source security news straight to your inbox.