10
CVSSv2

CVE-2004-0771

Published: 23/11/2004 Updated: 11/10/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in the extract_one function from lhext.c in LHA may allow malicious users to execute arbitrary code via a long w (working directory) command line option, a different issue than CVE-2004-0769. NOTE: this issue may be REJECTED if there are not any cases in which LHA is setuid or is otherwise used across security boundaries.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tsugio okamoto lha 1.14

tsugio okamoto lha 1.15

tsugio okamoto lha 1.17

Vendor Advisories

Synopsis lha security update Type/Severity Security Advisory: Important Topic An updated lha package that fixes a buffer overflow is now available Description LHA is an archiving and compression utility for LHarc format archivesLukasz Wojtow discovered a stack-based buffer overflow in all ...
Synopsis lha security update Type/Severity Security Advisory: Important Topic An updated lha package that fixes a buffer overflow is now available Description LHA is an archiving and compression utility for LHarc format archivesLukasz Wojtow discovered a stack-based buffer overflow in all ...

Exploits

//source: wwwsecurityfocuscom/bid/10354/info // //LHA has been reported prone to multiple vulnerabilities that may allow a malicious archive to execute arbitrary code or corrupt arbitrary files when the archive is operated on These issues are triggered in the 'extract_one()' and are due to a failure of the application to properly validate ...