Vulnerability Description
lrzsz before version 0.12.21~rc can leak information to the receiving side due to an incorrect length check in the function zsdata that causes a size_t to wrap around.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lrzsz Project | Lrzsz | <= 0.12.20 |
| Suse | Linux Enterprise Debuginfo | 11 |
| Suse | Linux Enterprise Desktop | 12 |
| Suse | Linux Enterprise Server | 11 |
| Debian | Debian Linux | 9.0 |
Related Weaknesses (CWE)
References
- http://www.ohse.de/uwe/software/lrzsz.htmlRelease NotesThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1572058Issue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/01/msg00027.htmlIssue TrackingMailing ListThird Party Advisory
- https://lists.suse.com/pipermail/sle-security-updates/2018-April/003955.html?_gaMailing ListThird Party Advisory
- https://lists.suse.com/pipermail/sle-security-updates/2018-April/003956.html?_gaMailing ListThird Party Advisory
- http://www.ohse.de/uwe/software/lrzsz.htmlRelease NotesThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1572058Issue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/01/msg00027.htmlIssue TrackingMailing ListThird Party Advisory
- https://lists.suse.com/pipermail/sle-security-updates/2018-April/003955.html?_gaMailing ListThird Party Advisory
- https://lists.suse.com/pipermail/sle-security-updates/2018-April/003956.html?_gaMailing ListThird Party Advisory
FAQ
What is CVE-2018-10195?
CVE-2018-10195 is a vulnerability with a CVSS score of 7.1 (HIGH). lrzsz before version 0.12.21~rc can leak information to the receiving side due to an incorrect length check in the function zsdata that causes a size_t to wrap around.
How severe is CVE-2018-10195?
CVE-2018-10195 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-10195?
Check the references section above for vendor advisories and patch information. Affected products include: Lrzsz Project Lrzsz, Suse Linux Enterprise Debuginfo, Suse Linux Enterprise Desktop, Suse Linux Enterprise Server, Debian Debian Linux.