Explzsh LHA File Processing Buffer Overflow Vulnerability
BID:41025
Info
Explzsh LHA File Processing Buffer Overflow Vulnerability
| Bugtraq ID: | 41025 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2010-2434 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 22 2010 12:00AM |
| Updated: | Apr 13 2015 09:02PM |
| Credit: | Kenju Takano |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Explzsh LHA File Processing Buffer Overflow Vulnerability
Explzsh is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Attackers may leverage this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
The issue affects Explzsh 5.62; prior versions may also be vulnerable.
Explzsh is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Attackers may leverage this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
The issue affects Explzsh 5.62; prior versions may also be vulnerable.
Exploit / POC
Explzsh LHA File Processing Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Explzsh LHA File Processing Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Explzsh LHA File Processing Buffer Overflow Vulnerability
References:
References:
- JVN#34729123: Explzh buffer overflow vulnerability (JVN)
- Explzh Advisory (pon software)