Bugzilla – Bug 1214590
VUL-0: CVE-2020-22916: xz: denial-of-service via decompression of crafted file
Last modified: 2023-10-11 10:05:10 UTC
CVE-2020-22916 An issue discovered in XZ 5.2.5 allows attackers to cause a denial of service via decompression of crafted file. The below github link is not working. Unclear about how this can be reproduced or if we have a fix. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-22916 https://www.cve.org/CVERecord?id=CVE-2020-22916 https://github.com/snappyJack/CVE-request-XZ-5.2.5-has-denial-of-service-vulnerability https://tukaani.org/xz/
Looking at the github issue in xz repository [1], it seems that this is not an actual issue. https://github.com/tukaani-project/xz/issues/61