Lrzsz has an integer overflow vulernability in the src/zm.c:zsdata() function. An attacker could exploit this with the sz command to cause a crash or potentially leak information to the receiving server. Additional References: https://bugzilla.novell.com/show_bug.cgi?id=1090051 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10195