Vendor
The lrz receive utility in lrzsz versions before 0.13.0 fails to properly sanitize absolute pathnames in restricted mode, allowing malicious ZMODEM senders to overwrite arbitrary files writable by the receiving user.