LHA多个代码执行漏洞

漏洞信息详情

LHA多个代码执行漏洞

漏洞简介

LHA存在缓冲区溢出漏洞。远程攻击者可以通过.LHZ档案中LHarc format 2 headers的超长路径名执行任意代码。正如开始时使用\”x\”选项但也被从\”l\”到\”v\”利用,并且固定在.c头部中,该问题不同于CVE-2004-0771。

漏洞公告

RedHat has released an advisory (RHSA-2004:323-09) to address these issues. Please see the advisory in Web references for more information.
RedHat has released an advisory (RHSA-2004:440-04) along with fixes to address these issues for RedHat Enterprise Linux operating systems. Please see the referenced advisory for further information.
RedHat Fedora has released advisories FEDORA-2004-294 and FEDORA-2004-295 dealing with these issues for their Core 1 and Core 2 products. Please see the referenced advisories for more information.
Gentoo has released advisory GLSA 200409-13 dealing with these issues. All LHa users should upgrade to the latest stable version with the following commands:
# emerge sync
# emerge -pv “>=app-arch/lha-114i-r4”
# emerge “>=app-arch/lha-114i-r4”
Please see the referenced Gentoo advisory for more information.
The Fedora Legacy project has released advisory FLSA:1833 along with fixes to address this issue in RedHat Linux 7.3. Please see the referenced advisory for further information.
Mr. S.K. LHA 1.14

参考网址

来源: bugs.gentoo.org
链接:http://bugs.gentoo.org/show_bug.cgi?id=51285

来源: FEDORA
名称: FLSA:1833
链接:https://bugzilla.fedora.us/show_bug.cgi?id=1833

来源: XF
名称: lha-long-pathname-bo(16917)
链接:http://xforce.iss.net/xforce/xfdb/16917

来源: REDHAT
名称: RHSA-2004:440
链接:http://www.redhat.com/support/errata/RHSA-2004-440.html

来源: GENTOO
名称: GLSA-200409-13
链接:http://www.gentoo.org/security/en/glsa/glsa-200409-13.xml

来源: OVAL
名称: oval:org.mitre.oval:def:11047
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11047

来源: lw.ftw.zamosc.pl
链接:http://lw.ftw.zamosc.pl/lha-exploit.txt

来源: BUGTRAQ
名称: 20040616 Re: [SECURITY] [DSA 515-1] New lha packages fix several vulnerabilities; Re:
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=108745217504379&w=2

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享