lrzsz before 0.13.0 contains a path traversal vulnerability in the lrz receive utility's restricted mode that allows malicious ZMODEM senders to write files outside the current directory using absolute pathnames. Because checkpath() in src/lrz.c only rejects '../' sequences unless built with --enable-pubdir, attackers can send files named with absolute paths to overwrite any file writable by the receiving user.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 06 Oct 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | lrzsz before 0.13.0 contains a path traversal vulnerability in the lrz receive utility's restricted mode that allows malicious ZMODEM senders to write files outside the current directory using absolute pathnames. Because checkpath() in src/lrz.c only rejects '../' sequences unless built with --enable-pubdir, attackers can send files named with absolute paths to overwrite any file writable by the receiving user. | |
| Title | lrzsz before 0.13.0 Path Traversal via lrz Restricted Mode checkpath() | |
| First Time appeared |
Lrzsz Project
Lrzsz Project lrzsz |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:lrzsz_project:lrzsz:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lrzsz Project
Lrzsz Project lrzsz |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-06T13:35:46.072Z
Reserved: 2026-10-05T22:00:10.842Z
Link: CVE-2026-105840
No data.
Status : Deferred
Published: 2026-10-06T14:17:41.300
Modified: 2026-10-06T15:25:00.650
Link: CVE-2026-105840
No data.
OpenCVE Enrichment
Updated: 2026-10-06T18:45:05Z
Weaknesses