WRITEUP

WRITEUP
Exploit for CVE-2025-67721 - Aircompressor <3.3 - Info Disclosure
AI Analysis

This patch addresses a data leak vulnerability in the Airlift LZ4 decompressor where a zero match offset could cause the decompressor to copy pre-existing data from the decompression buffer, potentially leaking sensitive information. The fix adds a boundary check to prevent this behavior.

Attack Type
info_leak
Complexity
moderate
Reliability
reliable
MITRE ATT&CK
T1005 - Data from Local System
Loading exploit code...
Download ZIP Password: eip
Authors
Martin Traverso
Vulnerability
CVE-2025-67721
Aircompressor <3.3 - Info Disclosure