bugs.gentoo.org
http://bugs.gentoo.org/show_bug.cgi?id=51285 CVE-2004-0771
LHA 1.x - 'extract_one' Multiple Buffer Overflow Vulnerabilities
Record summary
CVE-2004-0771 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.
Description
Buffer overflow in the extract_one function from lhext.c in LHA may allow attackers to execute arbitrary code via a long w (working directory) command line option, a different issue than CVE-2004-0769. NOTE: this issue may be REJECTED if there are not any cases in which LHA is setuid or is otherwise used across security boundaries.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBLHA 1.x - 'extract_one' Multiple Buffer Overflow VulnerabilitiesExploitDB exploitby Lukasz WojtowNot analyzed1 file
References
1120040606 Re: [SECURITY] [DSA 515-1] New lha packages fix severalmailing list
http://marc.info/?l=bugtraq&m=108668791510153 GLSA-200409-13Vendor advisory
http://www.gentoo.org/security/en/glsa/glsa-200409-13.xml RHSA-2004:323Vendor advisory
http://www.redhat.com/support/errata/RHSA-2004-323.html RHSA-2004:440Vendor advisory
http://www.redhat.com/support/errata/RHSA-2004-440.html 20040515 lha buffer overflow(s) againmailing list
http://www.securityfocus.com/archive/1/363418 10354vdb entry
http://www.securityfocus.com/bid/10354 FLSA:1833Vendor advisory
https://bugzilla.fedora.us/show_bug.cgi?id=1833 lha-extractone-bo(16196)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/16196 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-0771 oval:org.mitre.oval:def:9595vdb entrysignature
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9595