漏洞信息详情
LHA多个代码执行漏洞
- CNNVD编号:CNNVD-200409-088
- 危害等级: 超危
- CVE编号:
CVE-2004-0745
- 漏洞类型:
边界条件错误
- 发布时间:
2004-09-28
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
tsugio_okamoto - 漏洞来源:
Discovery is credi… -
漏洞简介
LHA 1.14及其早期版本存在漏洞。攻击者可以借助名称带有shell元字符的目录执行任意命令。
漏洞公告
RedHat has released an advisory (RHSA-2004:323-09) to address these issues. Please see the advisory in Web references for more information.
RedHat has released an advisory (RHSA-2004:440-04) along with fixes to address these issues for RedHat Enterprise Linux operating systems. Please see the referenced advisory for further information.
RedHat Fedora has released advisories FEDORA-2004-294 and FEDORA-2004-295 dealing with these issues for their Core 1 and Core 2 products. Please see the referenced advisories for more information.
Gentoo has released advisory GLSA 200409-13 dealing with these issues. All LHa users should upgrade to the latest stable version with the following commands:
# emerge sync
# emerge -pv “>=app-arch/lha-114i-r4”
# emerge “>=app-arch/lha-114i-r4”
Please see the referenced Gentoo advisory for more information.
The Fedora Legacy project has released advisory FLSA:1833 along with fixes to address this issue in RedHat Linux 7.3. Please see the referenced advisory for further information.
Mr. S.K. LHA 1.14
-
Fedora lha-1.14i-12.2.i386.rpmRedHat Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
Fedora lha-1.14i-12.2.x86_64.rpmRedHat Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
Fedora lha-1.14i-14.1.i386.rpmRedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora lha-1.14i-14.1.x86_64.rpmRedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora lha-debuginfo-1.14i-12.2.i386.rpmRedHat Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
Fedora lha-debuginfo-1.14i-12.2.x86_64.rpmRedHat Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
Fedora lha-debuginfo-1.14i-14.1.i386.rpmRedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora lha-debuginfo-1.14i-14.1.x86_64.rpmRedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
RedHat lha-1.14i-4.7.3.3.legacy.i386.rpmRedHat Linux 7.3
http://download.fedoralegacy.org/redhat/7.3/updates/i386/lha-1.14i-4.7
.3.3.legacy.i386.rpm -
RedHat lha-1.14i-9.4.legacy.i386.rpmRedHat Linux 9
http://download.fedoralegacy.org/redhat/9/updates/i386/lha-1.14i-9.4.l
egacy.i386.rpm
参考网址
来源: XF
名称: lha-metacharacter-command-execution(17198)
链接:http://xforce.iss.net/xforce/xfdb/17198
来源: REDHAT
名称: RHSA-2004:440
链接:http://www.redhat.com/support/errata/RHSA-2004-440.html
来源: FEDORA
名称: FLSA:1833
链接:https://bugzilla.fedora.us/show_bug.cgi?id=1833
来源: GENTOO
名称: GLSA-200409-13
链接:http://www.gentoo.org/security/en/glsa/glsa-200409-13.xml
来源: OVAL
名称: oval:org.mitre.oval:def:11088
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11088