Sceawere
Vulnerability Detail
CVE-2026-105840UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
lrzsz Path Traversal Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 11h ago
- Vendor
- Uwe Ohse
- Product
- lrzsz
- Attack Type
- Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
lrzsz before 0.13.0 contains a path traversal vulnerability in the lrz receive utility's restricted mode that allows malicious ZMODEM senders to write files outside the current directory using absolute pathnames. Because checkpath() in src/lrz.c only rejects '../' sequences unless built with --enable-pubdir, attackers can send files named with absolute paths to overwrite any file writable by the receiving user.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-06T14:17:41.300Z",
"pubdate": "2026-10-06T14:17:41.300Z",
"executiveSummary": "The lrzsz utility versions prior to 0.13.0 are susceptible to a critical path traversal vulnerability within the lrz receive component.\nThis vulnerability exists due to insufficient validation of filename strings received via the ZMODEM protocol when operating in restricted mode.\nA remote, malicious ZMODEM sender can leverage this flaw to bypass directory restrictions, enabling arbitrary file writes outside the intended destination directory.\nBy crafting a payload containing absolute pathnames, an attacker can overwrite sensitive system files or configuration data, provided the receiving process maintains sufficient filesystem permissions.\nThe vulnerability represents a significant security risk, as successful exploitation facilitates unauthorized filesystem access, potential privilege escalation, or system compromise by replacing binaries or configuration files with attacker-controlled content.\nExploitation requires the victim to initiate a file transfer session with a malicious ZMODEM sender, making the attack contingent on successful social engineering or the compromise of a remote ZMODEM endpoint.",
"technicalDetails": "The root cause of this vulnerability lies in the input validation logic within the checkpath() function located in src/lrz.c.\nIn versions prior to 0.13.0, the checkpath() function implementation specifically filters for '../' sequences to prevent directory traversal; however, it fails to adequately validate or sanitize absolute file paths provided by the ZMODEM sender.\nUnless the software is explicitly compiled with the --enable-pubdir configuration flag, the receive utility does not correctly restrict file placement to the current working directory.\nWhen a malicious sender transmits a filename starting with an absolute path (e.g., /etc/passwd or /root/.ssh/authorized_keys), the lrz utility improperly trusts the ZMODEM stream's metadata.\nBecause the logic fails to normalize or strip leading root directory indicators, the filesystem interface interprets the absolute path as the target destination for the file stream.\nThe attack flow proceeds as follows: First, an attacker establishes a ZMODEM session with a target utilizing a vulnerable version of lrz. Second, the attacker initiates a file transfer and manipulates the filename attribute within the ZMODEM header to include an absolute path targeting a sensitive system file. Third, the lrz process, executing with the permissions of the local user, attempts to create or overwrite the file at the specified absolute path. Finally, the file data sent by the attacker is written directly to the target location on the filesystem.\nThis vulnerability does not require authentication from the perspective of the ZMODEM protocol itself, as the exploitation occurs during the transport phase. The impact is limited only by the permissions of the user executing the lrz process; if the process is run by a superuser or a user with elevated write access, the impact can lead to full system compromise.\nThe lack of comprehensive path sanitization in the src/lrz.c component allows the ZMODEM protocol to be used as a vector for arbitrary filesystem writes, effectively turning a file transfer tool into an arbitrary file overwrite primitive."
}