lha Buffer Overflows Let Remote Users Create Malicious Archives to Execute Arbitrary Code
|
|
SecurityTracker Alert ID: 1009994 |
|
SecurityTracker URL: http://securitytracker.com/id/1009994
|
|
CVE Reference:
CAN-2004-0234, CAN-2004-0235
(Links to External Site)
|
Date: Apr 30 2004
|
Impact:
Execution of arbitrary code via network, Modification of system information, Modification of user information, User access via network
|
|
|
Description:
Several vulnerabilities were reported in the 'lha' LHarc archive processor. A remote user can create a malicious archive that will execute arbitrary code or write files to other directories on the system.
Red Hat reported that there are two stack buffer overflows and two directory traversal flaws in LHA.
A remote user can create a specially crafted LHA archive that, when loaded by the target user, will execute arbitrary code on the target user's system.
A remote user can also create a specially crafted LHA archive that, when expanded by the target user, will create files on the target user's system in a location outside of the current directory.
Ulf Harnhammar is credited with discovering these flaws.
|
Impact:
A remote user can create an archive that, when processed by a target user, will execute arbitrary code on the target user's system with the privileges of the target user or will create files on the target user's system that are located outside of the expected directory.
|
Solution:
No upstream solution was available at the time of this entry.
[Editor's note: Red Hat has issued a fix. See the Message History for a separate Alert regarding the Red Hat fix.]
|
Cause:
Access control error, Boundary error, Input validation error
|
Underlying OS:
Linux (Any), UNIX (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Fri, 30 Apr 2004 03:44:01 -0400
Subject: CAN-2004-0234, CAN-2004-0235
|
CVE: CAN-2004-0234, CAN-2004-0235
Red Hat reported that there are two stack buffer overflows and two directory traversal
flaws in LHA. A remote user can create a specially crafted LHA archive that, when loaded
by the target user, will execute arbitrary code on the target user's system.
Ulf Harnhammar is credited with discovering this flaw.
|
|