FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2004-0769

This CVE name corresponds to:

Entered Topic
2004-09-23 lha -- numerous vulnerabilities when extracting archives

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2004-0769
Phase Assigned(20040803)

Description

Buffer overflow in LHA allows remote attackers to execute arbitrary code via long pathnames in LHarc format 2 headers for a .LHZ archive, as originally demonstrated using the "x" option but also exploitable through "l" and "v", and fixed in header.c, a different issue than CVE-2004-0771.

References

Source Reference
BUGTRAQ 20040616 Re: [SECURITY] [DSA 515-1] New lha packages fix several vulnerabilities; Re:
MISC http://lw.ftw.zamosc.pl/lha-exploit.txt
FEDORA FLSA:1833
GENTOO GLSA-200409-13
REDHAT RHSA-2004:440
CONFIRM http://bugs.gentoo.org/show_bug.cgi?id=51285
REDHAT RHSA-2004:323
OVAL oval:org.mitre.oval:def:11047
XF lha-long-pathname-bo(16917)