FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2004-0771

This CVE name corresponds to:

Entered Topic
2004-09-23 lha -- numerous vulnerabilities when extracting archives

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2004-0771
Phase Assigned(20040804)

Description

Buffer overflow in the extract_one function from lhext.c in LHA may allow attackers to execute arbitrary code via a long w (working directory) command line option, a different issue than CVE-2004-0769. NOTE: this issue may be REJECTED if there are not any cases in which LHA is setuid or is otherwise used across security boundaries.

References

Source Reference
BUGTRAQ 20040515 lha buffer overflow(s) again
BUGTRAQ 20040606 Re: [SECURITY] [DSA 515-1] New lha packages fix several
MISC http://bugs.gentoo.org/show_bug.cgi?id=51285
FEDORA FLSA:1833
GENTOO GLSA-200409-13
REDHAT RHSA-2004:440
REDHAT RHSA-2004:323
OVAL oval:org.mitre.oval:def:9595
XF lha-extractone-bo(16196)
BID 10354