Debian 10264 Published by

A lrzsz security update has been released for Debian GNU/Linux 8 Extended LTS to address an information leak issue.



ELA-552-1 lrzsz security update

Package lrzsz
Version 0.12.21-7+deb8u1
Related CVEs CVE-2018-10195

An issues has been found in lrzsz, a set of tools for zmodem/xmodem/ymodem file transfer. Due to an incorrect length check, which might result in a size_t wrap around, an information leak to the receiving side could happen.

For Debian 8 jessie, these problems have been fixed in version 0.12.21-7+deb8u1.

We recommend that you upgrade your lrzsz packages.

Further information about Extended LTS security advisories can be found at: https://deb.freexian.com/extended-lts/

  ELA-552-1 lrzsz security update