The Lrzsz Project develops a narrowly scoped file-transfer utility that implements the X/Y/Z modem protocols for serial and network communication, a legacy but persistent component in embedded systems and terminal environments. Observed vulnerabilities in this tool center on integer overflow and wraparound conditions in protocol parsing, a characteristic weakness class in implementations of binary serial protocols that handle variable-length data and checksums.
The number and severity of CVEs published that impact products developed by Lrzsz Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-10195HIGH lrzsz before version 0.12.21~rc can leak information to the receiving side due to an incorrect length check in the function zsdata that causes a size_t to wrap around. | Jun 2, 2021 | 7.1 | 24 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lrzsz Project.
Media articles that mention a CVE ID that affects a product developed by Lrzsz Project — matched by CVE ID, not by vendor name.