-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2022.0366
                           lrzsz security update
                              27 January 2022

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           lrzsz
Publisher:         Debian
Operating System:  Debian GNU/Linux
Impact/Access:     Access Confidential Data -- Existing Account
                   Denial of Service        -- Existing Account
Resolution:        Patch/Upgrade
CVE Names:         CVE-2018-10195  

Original Bulletin: 
   https://lists.debian.org/debian-lts-announce/2022/01/msg00027.html

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- - -------------------------------------------------------------------------
Debian LTS Advisory DLA-2900-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                    Thorsten Alteholz
January 25, 2022                              https://wiki.debian.org/LTS
- - -------------------------------------------------------------------------

Package        : lrzsz
Version        : 0.12.21-8+deb9u1
CVE ID         : CVE-2018-10195


An issues has been found in lrzsz, a set of tools for zmodem/xmodem/ymodem 
file transfer.
Due to an incorrect length check, which might result in a size_t wrap 
around, an information leak to the receiving side could happen.


For Debian 9 stretch, this problem has been fixed in version
0.12.21-8+deb9u1.

We recommend that you upgrade your lrzsz packages.

For the detailed security status of lrzsz please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/lrzsz

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

- -----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAmHwdKpfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy
MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcACgkQlvysDTh7
WEfb6w//RtutOLAcIdNhoDpicQmZpdUw8Gh17yqrTUlTd90/0PmAfM0ZC2RDt/yr
CgXDZ77vJ8qjo+9IREpzSTR1hQpakSjKVb9a4y9kk1X4Sz0ZxvZugvHZUcou1Yzg
JN0hnukhXGwwRHr/JFbOkqm04JUCJ1afcVNuN9x1VPTZybb0NkdbN+35HEobwdXE
dsDVwq8bJGuYB12kviv8O0Mhot3g6zd1jQfTJUyvW9MjkuuTSo1eFHJPQ/J53kDr
6St3wRQhPzifjZCdjuMVj1utVj4siALUCBWP5V8VxWDh/ryUfWlbP+481oe78VQU
rvfkGMkZSDOAU5KI+37AkdlEgTaLtyY88rHljBDdZGzeMY925cTwSFLECy+RRLer
b0j0poV67uTZm5lgnxbSZb40B1CQmmKeY1eisf9FtZc2df6oyKQGGigS2mryXLqb
CGY1FPf+X3LoJ+G15M32GiXg4TjWz6wD4VaJh1pLHNnLNDAPE/56xAxO5rZNHfyn
yHUNAmzCSl1ftka4gmXmrUaWljFTd+cPayYRJQh4fQK8uk9PGJMYdfwyrmPP8cKz
IkBeH8e5qFLkUiYYqriLBgEFC4z5ogQMFEC2iiG1eaKAU6tUvsyCMQFjJeUcbjys
T9mjsCDIZfj9lfCWrifiBug3higrXwp3XLKeJw7Uz00a93jHqvk=
=qnzT
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBYfIj6eNLKJtyKPYoAQg/rg//ZJ2USOUcofoISRpUpYPeOZ4q9ICuDC4k
AMPGjoDJQTkYQ42eH5goaE5zBz8Dr1ZNx8kAqr0yuJ869NnmLQAm/KReQ7FQys2D
btoVjUdDBbs2NSnk+X3rOZnxZp6dzWNltQqBmmhS59u5PFTUgbqdwXUCw6Nc/qaC
vnTkQL+rx5KRlCri4k6kd/t7WhO6HFZcgTH4azPYOL1RwnzxROQW1mF5lDcC3yJQ
gClglPB6AgDpuHIXTqcrZH7AXcDX0jG+zde1UmIDVNRLwoFOx7ZlDBBpSPdv4sPl
s1637V9m2e56QA9FHeaZ2VkbhxGO7ePfnZJnD21WuoHPmmzP6EXCiAxsTXQwnb+H
cQRYYPH8aXhXGaEiRg9dkDmIA0HJ1rgnWTQl6MzoQyVzoR7Yy5jpvQMHljPesZBF
kRequ7dgAXZjmozEBA3hEBEOYKfkYoYSX3b/Jama9utJt3Yn6Ug2SjgyvK9poaDO
Fr6zcVdW1IPbKpJjsIuZlJj/ncMDEnci4lDH7bPGA1AvwMsPM0ApmZeQS6+lP/9P
CeNGp5wfEW7sgqn/2Lr45EGzTdklIBLC+Sg8KCwjpVKNrjJSmlBrdFEO0AjYf0NU
Oo0tgzF2BmRD+q27rzBLLa4UCLcXD7CdAViPFFJqqw3UKR0AkysnvUZ245h9AcZf
45HYU6jITIY=
=qviC
-----END PGP SIGNATURE-----