CVE-2004-0771: Buffer Overflow
Buffer overflow in the extractone function from lhext.c in LHA may allow attackers to execute arbitrary code via a long w (working directory) command line option, a different issue than CVE-2004-0769. NOTE: this issue may be REJECTED if there are not any cases in which LHA is setuid or is otherwise used across security boundaries.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0771?
CVE-2004-0771 is classified as a high-severity vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2004-0771?
To mitigate CVE-2004-0771, upgrade to LHA versions 1.18 or higher, which contain the necessary patches.
What systems are affected by CVE-2004-0771?
CVE-2004-0771 affects LHA versions 1.14, 1.15, and 1.17.
What type of vulnerability is CVE-2004-0771?
CVE-2004-0771 is a buffer overflow vulnerability that can lead to arbitrary code execution.
Who is the vendor associated with CVE-2004-0771?
The vendor associated with CVE-2004-0771 is Tsugio Okamoto, the creator of LHA.