LHA多个代码执行漏洞

漏洞信息详情

LHA多个代码执行漏洞

漏洞简介

LHA 1.14及其早期版本存在漏洞。攻击者可以借助名称带有shell元字符的目录执行任意命令。

漏洞公告

RedHat has released an advisory (RHSA-2004:323-09) to address these issues. Please see the advisory in Web references for more information.
RedHat has released an advisory (RHSA-2004:440-04) along with fixes to address these issues for RedHat Enterprise Linux operating systems. Please see the referenced advisory for further information.
RedHat Fedora has released advisories FEDORA-2004-294 and FEDORA-2004-295 dealing with these issues for their Core 1 and Core 2 products. Please see the referenced advisories for more information.
Gentoo has released advisory GLSA 200409-13 dealing with these issues. All LHa users should upgrade to the latest stable version with the following commands:
# emerge sync
# emerge -pv “>=app-arch/lha-114i-r4”
# emerge “>=app-arch/lha-114i-r4”
Please see the referenced Gentoo advisory for more information.
The Fedora Legacy project has released advisory FLSA:1833 along with fixes to address this issue in RedHat Linux 7.3. Please see the referenced advisory for further information.
Mr. S.K. LHA 1.14

参考网址

来源: XF
名称: lha-metacharacter-command-execution(17198)
链接:http://xforce.iss.net/xforce/xfdb/17198

来源: REDHAT
名称: RHSA-2004:440
链接:http://www.redhat.com/support/errata/RHSA-2004-440.html

来源: FEDORA
名称: FLSA:1833
链接:https://bugzilla.fedora.us/show_bug.cgi?id=1833

来源: GENTOO
名称: GLSA-200409-13
链接:http://www.gentoo.org/security/en/glsa/glsa-200409-13.xml

来源: OVAL
名称: oval:org.mitre.oval:def:11088
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11088

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享