LHA Multiple extract_one Buffer Overflow Vulnerabilities
BID:10354
Info
LHA Multiple extract_one Buffer Overflow Vulnerabilities
| Bugtraq ID: | 10354 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-0771 |
| Remote: | Yes |
| Local: | No |
| Published: | May 15 2004 12:00AM |
| Updated: | Jul 12 2009 04:07AM |
| Credit: | Discovery of this issue is credited to Lukasz Wojtow <[email protected]>. |
| Vulnerable: |
Mr. S.K. LHA 1.17 Mr. S.K. LHA 1.15 Mr. S.K. LHA 1.14 F-Secure Personal Express 4.7 F-Secure Personal Express 4.6 F-Secure Personal Express 4.5 F-Secure Internet Security 2004 F-Secure Internet Security 2003 F-Secure Internet Gatekeeper 6.32 F-Secure Internet Gatekeeper 6.31 F-Secure F-Secure for Firewalls 6.20 F-Secure Anti-Virus for Workstations 5.42 F-Secure Anti-Virus for Workstations 5.41 F-Secure Anti-Virus for Windows Servers 5.42 F-Secure Anti-Virus for Windows Servers 5.41 F-Secure Anti-Virus for Samba Servers 4.60 F-Secure Anti-Virus for MS Exchange 6.21 F-Secure Anti-Virus for MIMEsweeper 5.42 F-Secure Anti-Virus for MIMEsweeper 5.41 F-Secure Anti-Virus for Linux Workstations 4.52 F-Secure Anti-Virus for Linux Workstations 4.51 F-Secure Anti-Virus for Linux Servers 4.52 F-Secure Anti-Virus for Linux Servers 4.51 F-Secure Anti-Virus for Linux Gateways 4.52 F-Secure Anti-Virus for Linux Gateways 4.51 F-Secure Anti-Virus Client Security 5.52 F-Secure Anti-Virus Client Security 5.50 F-Secure Anti-Virus 2004 F-Secure Anti-Virus 2003 |
| Not Vulnerable: | |
Discussion
LHA Multiple extract_one Buffer Overflow Vulnerabilities
LHA has been reported prone to multiple vulnerabilities that may allow a malicious archive to execute arbitrary code or corrupt arbitrary files when the archive is operated on. These issues are triggered in the 'extract_one()' and are due to a failure of the application to properly validate string lengths in offending files.
These issues might allow an attacker to execute code in the context of a user invoking the affected utility.
LHA has been reported prone to multiple vulnerabilities that may allow a malicious archive to execute arbitrary code or corrupt arbitrary files when the archive is operated on. These issues are triggered in the 'extract_one()' and are due to a failure of the application to properly validate string lengths in offending files.
These issues might allow an attacker to execute code in the context of a user invoking the affected utility.
Exploit / POC
LHA Multiple extract_one Buffer Overflow Vulnerabilities
The following proof of concept exploit code is available:
The following proof of concept exploit code is available:
Solution / Fix
LHA Multiple extract_one Buffer Overflow Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
LHA Multiple extract_one Buffer Overflow Vulnerabilities
References:
References:
- LHA for UNIX Version 1.17 (LHA for UNIX)
- lha buffer overflow(s) again (Lukasz Wojtow
) - Re: [SECURITY] [DSA 515-1] New lha packages fix several vulnerabilities (
)