CVE-2015-0906

Lhaplus < 1.70 - Path Traversal and Arbitrary File Write via Crafted Archive

Title source: llm
STIX 2.1

Description

Directory traversal vulnerability in Lhaplus before 1.70 allows remote attackers to write to arbitrary files via a crafted archive.

References (4)

Core 4
Core References
Vendor Advisory third-party-advisory x_refsource_jvn
http://jvn.jp/en/jp/JVN02527990/index.html
Vendor Advisory third-party-advisory x_refsource_jvndb
http://jvndb.jvn.jp/jvndb/JVNDB-2015-000050
Various Sources x_refsource_confirm
http://www7a.biglobe.ne.jp/~schezo/
Third Party Advisory x_refsource_confirm
http://jvn.jp/en/jp/JVN02527990/414318/index.html

Scores

EPSS 0.0156
EPSS Percentile 72.2%

Details

CWE
CWE-22
Status published
Products (6)
lhaplus/lhaplus 1.52
lhaplus/lhaplus 1.53
lhaplus/lhaplus 1.55
lhaplus/lhaplus 1.56
lhaplus/lhaplus 1.57
lhaplus/lhaplus < 1.59
Published Apr 15, 2015
Tracked Since Feb 18, 2026