www.vulncheck.com Lrzsz Vulnerabilities: OS Command Injection and Path Traversal Risks
Article Content
- •Two critical vulnerabilities in lrzsz before version 0.13.0: OS command injection and path traversal.
- •CWE-78 and CWE-22 vulnerabilities could allow attackers to execute commands and access unauthorized files.
- •Users are advised to upgrade to lrzsz version 0.13.0 to mitigate these risks.
Two vulnerabilities have been identified in lrzsz versions prior to 0.13.0. The first, a command injection flaw (CWE-78), allows attackers to execute arbitrary OS commands via the lrz pipe mode. The second, a path traversal vulnerability (CWE-22), enables unauthorized file access through the lrz restricted mode checkpath. Both vulnerabilities could potentially be exploited by attackers to compromise systems using lrzsz. Security updates have been released to address these issues. Users are urged to upgrade to version 0.13.0 or later to mitigate risks. No has been reported as of now, but the vulnerabilities are significant enough to warrant immediate attention from system administrators.
Ask AI about this cluster
Answers cite the sources they use