Bug 1214590 (CVE-2020-22916) - VUL-0: CVE-2020-22916: xz: denial-of-service via decompression of crafted file
Summary: VUL-0: CVE-2020-22916: xz: denial-of-service via decompression of crafted file
Status: NEW
Alias: CVE-2020-22916
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Minor
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/375984/
Whiteboard: CVSSv3.1:SUSE:CVE-2020-22916:3.3:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2023-08-24 15:05 UTC by Alexander Bergmann
Modified: 2023-10-11 10:05 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2023-08-24 15:05:54 UTC
CVE-2020-22916

An issue discovered in XZ 5.2.5 allows attackers to cause a denial of service
via decompression of crafted file.

The below github link is not working. Unclear about how this can be reproduced or if we have a fix.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-22916
https://www.cve.org/CVERecord?id=CVE-2020-22916
https://github.com/snappyJack/CVE-request-XZ-5.2.5-has-denial-of-service-vulnerability
https://tukaani.org/xz/
Comment 1 Danilo Spinella 2023-10-11 10:05:10 UTC
Looking at the github issue in xz repository [1], it seems that this is not an actual issue.

https://github.com/tukaani-project/xz/issues/61