Back

MEDIUM

lhaca issue might affect lha packages

Published Jun 25, 2007

Description

Stack-based buffer overflow in Lhaca File Archiver before 1.21 allows user-assisted remote attackers to execute arbitrary code via a crafted LZH archive, as exploited by malware such as Trojan.Lhdropper.

Affected products

Remediation

Red Hat statement

Not vulnerable, Red Hat do not ship the Lhaca file archiver. Note that an identical flaw was found affecting the lha file archiver in 2004, CVE-2004-0234. This issue was corrected by security update RHSA-2004:178 for Red Hat Enterprise Linux 2.1 and 3. Red Hat Enterprise Linux 4 was not vulnerable as it contained a backported patch to correct this issue from release.

Metrics

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 25, 2007
Updated Aug 7, 2024
Reserved Jun 25, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Jul 1, 2007