First published: Fri Sep 10 2004(Updated: )
LHA 1.14 and earlier allows attackers to execute arbitrary commands via a directory with shell metacharacters in its name.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
LHA (by Tsugio Okamoto) | <=1.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0745 is classified as a critical vulnerability due to its potential to allow arbitrary command execution.
To fix CVE-2004-0745, upgrade to LHA version 1.15 or later.
The implications of CVE-2004-0745 include potential unauthorized access and execution of commands on the affected system.
CVE-2004-0745 affects users of LHA versions 1.14 and earlier.
Mitigation options for CVE-2004-0745 are limited, and the safest approach is to upgrade the software.