CVE-2018-10195 is a high-severity information leakage vulnerability affecting lrzsz versions prior to 0.12.21~rc, impacting Debian and SUSE products. The flaw stems from an incorrect length check in the zsdata function, leading to a size_t integer wraparound. This local vulnerability, requiring low privileges and no user interaction, could result in high confidentiality and availability impacts. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.12.20CPE matchmatch criteria | cpe:2.3:a:lrzsz_project:lrzsz:*:*:*:*:*:*:*:* | ||
11CPE matchmatch criteria | cpe:2.3:a:suse:linux_enterprise_debuginfo:11:sp4:*:*:*:*:*:* | ||
12CPE matchmatch criteria | cpe:2.3:o:suse:linux_enterprise_desktop:12:sp3:*:*:*:*:*:* | ||
11CPE matchmatch criteria | cpe:2.3:o:suse:linux_enterprise_server:11:sp4:*:*:*:*:*:* | ||
12CPE matchmatch criteria | cpe:2.3:o:suse:linux_enterprise_server:12:sp3:*:*:-:-:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
lrzsz before version 0.12.21~rc can leak information to the receiving side due to an incorrect length check in the function zsdata that causes a size_t to wrap around.
Jun 8, 2021lrzsz: Integer overflow in src/zm.c:zsdata() causes crash in sz and can leak information to receiver
Apr 18, 2018