5.5
CVSSv3

CVE-2020-22916

Published: 22/08/2023 Updated: 17/05/2024
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

An issue discovered in XZ 5.2.5 allows malicious users to cause a denial of service via decompression of a crafted file. NOTE: the vendor disputes the claims of "endless output" and "denial of service" because decompression of the 17,486 bytes always results in 114,881,179 bytes, which is often a reasonable size increase.

Vulnerable Product Search on Vulmon Subscribe to Product

tukaani xz 5.2.5

Vendor Advisories

DescriptionThe MITRE CVE dictionary describes this issue as: An issue discovered in XZ 525 allows attackers to cause a denial of service via decompression of crafted file ...