The Long Range Zip Project maintains a focused compression utility whose vulnerability footprint, while modest in product scope, recurs across a prominent niche of archival and file-handling workloads. Its disclosures cluster around memory-safety and control-flow weaknesses characteristic of native-code compression libraries: use-after-free conditions, NULL-pointer dereferences, buffer-boundary violations, infinite loops, and out-of-bounds reads that reflect the parser complexity and performance-critical design of zip decompression. These classes of flaws in compression tools can propagate broadly through downstream consumers—particularly backup systems, archive processors, and file managers—where malformed archives may be processed with elevated privilege or in automated contexts. Defenders should treat this vendor's patches as relevant to any pipeline that handles untrusted archives and should inventory deployments where the library is embedded; current severity, exploitation activity, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Long Range Zip Project over time
Signals from CVEs in this vendor scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-10685CRITICAL In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the lzma_decompress_buf function of stream.c, which allows remote attackers to cause a denial of service (applicat | May 2, 2018 | 9.8 | 30 | NO | NO |
CVE-2017-8844HIGH The read_1g function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly h | May 8, 2017 | 7.8 | 26 | NO | NO |
CVE-2021-33453HIGH An issue was discovered in lrzip version 0.641. There is a use-after-free in ucompthread() in stream.c:1538. | Jul 26, 2022 | 7.8 | 24 | NO | NO |
CVE-2018-11496MEDIUM In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in read_stream in stream.c, because decompress_file in lrzip.c lacks certain size validation. | May 26, 2018 | 6.5 | 23 | NO | NO |
CVE-2022-26291MEDIUM lrzip v0.641 was discovered to contain a multiple concurrency use-after-free between the functions zpaq_decompress_buf() and clear_rulist(). This vulnerability allows attackers to | Mar 28, 2022 | 5.5 | 21 | NO | NO |
CVE-2018-5786MEDIUM In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the get_fileinfo function (lrzip.c). Remote attackers could leverage this vulnerability to ca | Jan 19, 2018 | 5.5 | 21 | NO | NO |
CVE-2018-5747MEDIUM In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the ucompthread function (stream.c). Remote attackers could leverage this vulnerability to cause a denial of servi | Jan 17, 2018 | 5.5 | 21 | NO | NO |
CVE-2018-5650MEDIUM In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the unzip_match function in runzip.c. Remote attackers could leverage this vulnerability to c | Jan 12, 2018 | 5.5 | 21 | NO | NO |
CVE-2017-9929MEDIUM In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:1074, which allows attackers to cause a denial of service via a crafted file. | Jun 26, 2017 | 5.5 | 21 | NO | NO |
CVE-2017-9928MEDIUM In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:979, which allows attackers to cause a denial of service via a crafted file. | Jun 26, 2017 | 5.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (23 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Long Range Zip Project.
Media articles that mention a CVE ID that affects a product developed by Long Range Zip Project — matched by CVE ID, not by vendor name.