Family: Fedora Local Security Checks --> Category: infos
Fedora Core 1 2004-119: lha Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the lha package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory FEDORA-2004-119 (lha).
LHA is an archiving and compression utility for LHarc format archives.
LHA is mostly used in the DOS world, but can be used under Linux to
extract DOS files from LHA archives.
Install the lha package if you need to extract DOS files from LHA archives.
Ulf Härnhammar discovered two stack buffer overflows and two directory
traversal flaws in LHA. A possible hacker could exploit the buffer
overflows by creating a carefully crafted LHA archive in such a way
that arbitrary code would be executed when the archive is tested or
extracted by a victim. CVE-2004-0234. A possible hacker could exploit the
directory traversal issues to create files as the victim outside of
the expected directory. CVE-2004-0235.
Solution : http://www.fedoranews.org/updates/FEDORA-2004-119.shtml
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.