漏洞信息详情
LHA多个代码执行漏洞
- CNNVD编号:CNNVD-200408-189
- 危害等级: 超危
- CVE编号:
CVE-2004-0769
- 漏洞类型:
缓冲区溢出
- 发布时间:
2004-08-18
- 威胁类型:
远程
- 更新时间:
2005-10-28
- 厂 商:
mozilla - 漏洞来源:
Discovery is credi… -
漏洞简介
LHA存在缓冲区溢出漏洞。远程攻击者可以通过.LHZ档案中LHarc format 2 headers的超长路径名执行任意代码。正如开始时使用\”x\”选项但也被从\”l\”到\”v\”利用,并且固定在.c头部中,该问题不同于CVE-2004-0771。
漏洞公告
RedHat has released an advisory (RHSA-2004:323-09) to address these issues. Please see the advisory in Web references for more information.
RedHat has released an advisory (RHSA-2004:440-04) along with fixes to address these issues for RedHat Enterprise Linux operating systems. Please see the referenced advisory for further information.
RedHat Fedora has released advisories FEDORA-2004-294 and FEDORA-2004-295 dealing with these issues for their Core 1 and Core 2 products. Please see the referenced advisories for more information.
Gentoo has released advisory GLSA 200409-13 dealing with these issues. All LHa users should upgrade to the latest stable version with the following commands:
# emerge sync
# emerge -pv “>=app-arch/lha-114i-r4”
# emerge “>=app-arch/lha-114i-r4”
Please see the referenced Gentoo advisory for more information.
The Fedora Legacy project has released advisory FLSA:1833 along with fixes to address this issue in RedHat Linux 7.3. Please see the referenced advisory for further information.
Mr. S.K. LHA 1.14
-
Fedora lha-1.14i-12.2.i386.rpmRedHat Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
Fedora lha-1.14i-12.2.x86_64.rpmRedHat Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
Fedora lha-1.14i-14.1.i386.rpmRedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora lha-1.14i-14.1.x86_64.rpmRedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora lha-debuginfo-1.14i-12.2.i386.rpmRedHat Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
Fedora lha-debuginfo-1.14i-12.2.x86_64.rpmRedHat Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
Fedora lha-debuginfo-1.14i-14.1.i386.rpmRedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora lha-debuginfo-1.14i-14.1.x86_64.rpmRedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
RedHat lha-1.14i-4.7.3.3.legacy.i386.rpmRedHat Linux 7.3
http://download.fedoralegacy.org/redhat/7.3/updates/i386/lha-1.14i-4.7
.3.3.legacy.i386.rpm -
RedHat lha-1.14i-9.4.legacy.i386.rpmRedHat Linux 9
http://download.fedoralegacy.org/redhat/9/updates/i386/lha-1.14i-9.4.l
egacy.i386.rpm
参考网址
来源: bugs.gentoo.org
链接:http://bugs.gentoo.org/show_bug.cgi?id=51285
来源: FEDORA
名称: FLSA:1833
链接:https://bugzilla.fedora.us/show_bug.cgi?id=1833
来源: XF
名称: lha-long-pathname-bo(16917)
链接:http://xforce.iss.net/xforce/xfdb/16917
来源: REDHAT
名称: RHSA-2004:440
链接:http://www.redhat.com/support/errata/RHSA-2004-440.html
来源: GENTOO
名称: GLSA-200409-13
链接:http://www.gentoo.org/security/en/glsa/glsa-200409-13.xml
来源: OVAL
名称: oval:org.mitre.oval:def:11047
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11047
来源: lw.ftw.zamosc.pl
链接:http://lw.ftw.zamosc.pl/lha-exploit.txt
来源: BUGTRAQ
名称: 20040616 Re: [SECURITY] [DSA 515-1] New lha packages fix several vulnerabilities; Re:
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=108745217504379&w=2