CVE-2020-22916: Medium severity tukaani xz vulnerability
DISPUTED An issue discovered in XZ 5.2.5 allows attackers to cause a denial of service via decompression of a crafted file. NOTE: the vendor disputes the claims of "endless output" and "denial of service" because decompression of the 17,486 bytes always results in 114,881,179 bytes, which is often a reasonable size increase.
Other sources
An issue discovered in XZ 5.2.5 allows attackers to cause a denial of service via decompression of crafted file.
References:
https://tukaani.org/xz/ https://github.com/snappyJack/CVE-request-XZ-5.2.5-has-denial-of-service-vulnerability
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-22916?
CVE-2020-22916 is a vulnerability discovered in XZ version 5.2.5 that allows attackers to cause a denial of service by exploiting a crafted file during decompression.
What is the severity of CVE-2020-22916?
The severity of CVE-2020-22916 is medium with a severity value of 5.5.
How can I fix CVE-2020-22916?
To fix CVE-2020-22916, update to a version of XZ that is not affected by this vulnerability, if available. Ensure you are using the latest version and follow any provided patches or updates from the vendor.
Is there any dispute regarding CVE-2020-22916?
Yes, there is a dispute regarding CVE-2020-22916 as the vendor disputes the claims of "endless output" and "denial of service" associated with the vulnerability.
Where can I find more information about CVE-2020-22916?
You can find more information about CVE-2020-22916 on the Debian Security Tracker page, the official Tukaani XZ website, and the GitHub repository that reported the vulnerability.