CVE-2018-10685

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
02/05/2018
Last modified:
02/08/2021

Description

In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the lzma_decompress_buf function of stream.c, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:long_range_zip_project:long_range_zip:0.631:*:*:*:*:*:*:*