Logo
vulnerabilityCVE-2022-33067
Name
CVE-2022-33067
Source
NVD ( link)Debian ( link)
Description
Lrzip v0.651 was discovered to contain multiple invalid arithmetic shifts via the functions get_magic in lrzip.c and Predictor::init in libzpaq/libzpaq.cpp. These vulnerabilities allow attackers to cause a Denial of Service via unspecified vectors.
CWEs
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
lrzip
Exploitable

Vulnerability Ratings#


5.5
CVSSv31
4.3
CVSSv2

Others affected component#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
0.651
Exploitable