buildroot ▾
›
2025.02.x ▾
›
vulnerability
›
CVE-2023-39741
Component Overview
Vulnerability Overview
Name
CVE-2023-39741
Source
NVD (
link
)
Debian (
link
)
Description
lrzip v0.651 was discovered to contain a heap overflow via the libzpaq::PostProcessor::write(int) function at /libzpaq/libzpaq.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.
CWEs
CWE-787
Published Date
Aug 17, 2023
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/ckolivas/lrzip/issues/246
Exploit
https://github.com/huanglei3/lrzip_poc/tree/main/lrzip_heap_overflow
Exploit
https://github.com/ckolivas/lrzip/issues/246
Exploit
https://github.com/huanglei3/lrzip_poc/tree/main/lrzip_heap_overflow
Exploit
Analysis
#
Affected Component
Analysis
lrzip
Exploitable
Vulnerability Ratings
#
5.5
CVSSv31
NaN
other
Others affected component
#
Name
Project
Project Version
Version
Status
lrzip
buildroot
master
0.651
Exploitable