PT-2023-11638 · Xz+2 · Xz+2

·

CVE-2020-22916

·

Published

2023-08-22

·

Updated

2024-11-05

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions XZ version 5.2.5
Description An issue in XZ allows attackers to cause a denial of service via decompression of a crafted file. The vendor disputes the claims of "endless output" and "denial of service" because decompression of a 17,486 bytes file always results in 114,881,179 bytes, which is often a reasonable size increase.
Recommendations For XZ version 5.2.5, update to version 5.2.9 to fix the security issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2024-1246
ALT-PU-2024-14986
ALT-PU-2024-8803
CVE-2020-22916

Affected Products

Alt Linux
Xz
Xz Utils