CVE-2020-22916

Name
CVE-2020-22916
Description
An issue discovered in XZ 5.2.5 allows attackers to cause a denial of service via decompression of crafted file.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://tukaani.org/xz/
MISC https://github.com/snappyJack/CVE-request-XZ-5.2.5-has-denial-of-service-vulnerability

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:tukaani:xz:5.2.5:*:*:*:*:*:*:* xz == None == 5.2.5

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
xz 3.16-main 5.2.5-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
xz 3.15-main 5.2.5-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable