<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Lrzsz - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/lrzsz/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 06 Oct 2026 14:56:09 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/lrzsz/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Path Traversal in lrzsz lrz Utility</title><link>https://feed.craftedsignal.io/briefs/2026-10-lrzsz-path-traversal/</link><pubDate>Tue, 06 Oct 2026 14:56:09 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-lrzsz-path-traversal/</guid><description>The lrz receive utility in lrzsz versions before 0.13.0 fails to properly sanitize absolute pathnames in restricted mode, allowing malicious ZMODEM senders to overwrite arbitrary files writable by the receiving user.</description><content:encoded><![CDATA[<p>The lrz utility, part of the lrzsz package used for X/Y/ZMODEM file transfers, contains a path traversal vulnerability (CVE-2026-105840) in its restricted mode. This vulnerability stems from the checkpath() function in src/lrz.c, which fails to adequately filter absolute pathnames. While the software attempts to reject '../' traversal sequences, it does not account for absolute paths when not compiled with the --enable-pubdir option. An attacker acting as a ZMODEM sender can leverage this flaw to write or overwrite files outside the intended destination directory, provided the user running lrz has the necessary file system permissions. This vulnerability is particularly critical in environments where lrz is used to facilitate automated file uploads, as it allows for arbitrary file write scenarios that can lead to remote code execution or system configuration compromise if sensitive files like .ssh/authorized_keys or shell profiles are targeted.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an unauthenticated remote attacker or a malicious ZMODEM sender to overwrite system files or user-specific configuration files. This can result in privilege escalation, persistence establishment, or remote code execution, depending on the privileges of the account executing the lrz process. The vulnerability affects all systems utilizing lrzsz versions prior to 0.13.0 for ZMODEM file transfers.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade lrzsz to version 0.13.0 or later immediately to patch CVE-2026-105840.</li>
<li>Audit any automated scripts or services that invoke the lrz binary to ensure they are not exposing the application to untrusted ZMODEM senders.</li>
<li>Run the lrz process with the least privilege possible, utilizing restricted user accounts that lack write access to sensitive system directories or user configuration files.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>