LHA多个代码执行漏洞

admin 2022-07-22 12:49:03 CNNVD漏洞 来源:ZONE.CI 全球网 0 阅读模式

漏洞信息详情

LHA多个代码执行漏洞

  • CNNVD编号:CNNVD-200408-189
  • 危害等级: 超危
  • CVE编号: CVE-2004-0769
  • 漏洞类型: 缓冲区溢出
  • 发布时间: 2004-08-18
  • 威胁类型: 远程
  • 更新时间: 2005-10-28
  • 厂        商: mozilla
  • 漏洞来源: Discovery is credi...

漏洞简介

LHA存在缓冲区溢出漏洞。远程攻击者可以通过.LHZ档案中LHarc format 2 headers的超长路径名执行任意代码。正如开始时使用\"x\"选项但也被从\"l\"到\"v\"利用,并且固定在.c头部中,该问题不同于CVE-2004-0771。

漏洞公告

RedHat has released an advisory (RHSA-2004:323-09) to address these issues. Please see the advisory in Web references for more information. RedHat has released an advisory (RHSA-2004:440-04) along with fixes to address these issues for RedHat Enterprise Linux operating systems. Please see the referenced advisory for further information. RedHat Fedora has released advisories FEDORA-2004-294 and FEDORA-2004-295 dealing with these issues for their Core 1 and Core 2 products. Please see the referenced advisories for more information. Gentoo has released advisory GLSA 200409-13 dealing with these issues. All LHa users should upgrade to the latest stable version with the following commands: # emerge sync # emerge -pv ">=app-arch/lha-114i-r4" # emerge ">=app-arch/lha-114i-r4" Please see the referenced Gentoo advisory for more information. The Fedora Legacy project has released advisory FLSA:1833 along with fixes to address this issue in RedHat Linux 7.3. Please see the referenced advisory for further information. Mr. S.K. LHA 1.14

  • Fedora lha-1.14i-12.2.i386.rpmRedHat Fedora Core 1 http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
  • Fedora lha-1.14i-12.2.x86_64.rpmRedHat Fedora Core 1 http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
  • Fedora lha-1.14i-14.1.i386.rpmRedHat Fedora Core 2 http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
  • Fedora lha-1.14i-14.1.x86_64.rpmRedHat Fedora Core 2 http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
  • Fedora lha-debuginfo-1.14i-12.2.i386.rpmRedHat Fedora Core 1 http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
  • Fedora lha-debuginfo-1.14i-12.2.x86_64.rpmRedHat Fedora Core 1 http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
  • Fedora lha-debuginfo-1.14i-14.1.i386.rpmRedHat Fedora Core 2 http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
  • Fedora lha-debuginfo-1.14i-14.1.x86_64.rpmRedHat Fedora Core 2 http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
  • RedHat lha-1.14i-4.7.3.3.legacy.i386.rpmRedHat Linux 7.3 http://download.fedoralegacy.org/redhat/7.3/updates/i386/lha-1.14i-4.7 .3.3.legacy.i386.rpm
  • RedHat lha-1.14i-9.4.legacy.i386.rpmRedHat Linux 9 http://download.fedoralegacy.org/redhat/9/updates/i386/lha-1.14i-9.4.l egacy.i386.rpm

参考网址

来源: bugs.gentoo.org 链接:http://bugs.gentoo.org/show_bug.cgi?id=51285 来源: FEDORA 名称: FLSA:1833 链接:https://bugzilla.fedora.us/show_bug.cgi?id=1833 来源: XF 名称: lha-long-pathname-bo(16917) 链接:http://xforce.iss.net/xforce/xfdb/16917 来源: REDHAT 名称: RHSA-2004:440 链接:http://www.redhat.com/support/errata/RHSA-2004-440.HTML 来源: GENTOO 名称: GLSA-200409-13 链接:http://www.gentoo.org/security/en/glsa/glsa-200409-13.xml 来源: OVAL 名称: oval:org.mitre.oval:def:11047 链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11047 来源: lw.ftw.zamosc.pl 链接:http://lw.ftw.zamosc.pl/lha-exploit.txt 来源: BUGTRAQ 名称: 20040616 Re: [SECURITY] [DSA 515-1] New lha packages fix several vulnerabilities; Re: 链接:http://marc.theaimsgroup.com/?l=bugtraq&m=108745217504379&w=2

受影响实体

  • Mozilla Bugzilla  

补丁

    暂无

weinxin
特别声明
本站(ZONE.CI)所有文章仅供技术研究,若将其信息做其他用途,由用户承担全部法律及连带责任,本站不承担任何法律及连带责任,请遵守中华人民共和国安全法.
Mac OS X漏洞 CNNVD漏洞

Mac OS X漏洞

漏洞信息详情Mac OS X漏洞CNNVD编号:CNNVD-200408-192危害等级: 高危CVE编号:CVE-2004-0514漏洞类型:未知发布时间:2004-08-1
LHA多个代码执行漏洞 CNNVD漏洞

LHA多个代码执行漏洞

漏洞信息详情LHA多个代码执行漏洞CNNVD编号:CNNVD-200408-189危害等级: 超危CVE编号:CVE-2004-0769漏洞类型:缓冲区溢出发布时间:2004-
评论:0   参与:  0