Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

tukaani-project — Vulnerabilities & Security Advisories 3

Browse all 3 CVE security advisories affecting tukaani-project. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The tukaani-project develops the XZ Utils data compression software, widely used for efficient file compression across Linux distributions. Historically, the project has faced vulnerabilities including remote code execution flaws in decompression functions and buffer overflow issues in parsing compressed data. While no major public security incidents have been documented, the three CVEs on record highlight potential risks in handling malformed input files. The project's security characteristics emphasize robust input validation and careful memory management to prevent exploitation, though its position in critical system infrastructure makes any vulnerability particularly impactful for downstream users relying on its compression capabilities.

Top products by tukaani-project: xz

This page lists every published CVE security advisory associated with tukaani-project. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.