CVE-2004-0769 Information
Description
Buffer overflow in LHA allows remote attackers to execute arbitrary code via long pathnames in LHarc format 2 headers for a .LHZ archive as originally demonstrated using the \x\ option but also exploitable through \l\ and \v\ and fixed in header.c a different issue than CVE-2004-0771.
Reference
http://bugs.gentoo.org/show_bug.cgi?id=51285 http://lw.ftw.zamosc.pl/lha-exploit.txt http://marc.info/?l=bugtraq&m=108745217504379&w=2 http://www.gentoo.org/security/en/glsa/glsa-200409-13.xml http://www.redhat.com/support/errata/RHSA-2004-323.html http://www.redhat.com/support/errata/RHSA-2004-440.html https://bugzilla.fedora.us/show_bug.cgi?id=1833 https://exchange.xforce.ibmcloud.com/vulnerabilities/16917 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A11047
Share on: