Buffer overflow in LHA allows remote attackers to execute arbitrary code via long pathnames in LHarc format 2 headers for a .LHZ archive, as originally demonstrated using the x option but also exploitable through l and v, and fixed in header.c, a different issue than CVE-2004-0771.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Bugzilla | Mozilla | * | * |
| Red Hat Enterprise Linux 3 | RedHat | lha-0:1.14i-10.4 | * |
| Red Hat Enterprise Linux AS (Advanced Server) version 2.1 | RedHat | * | |
| Red Hat Enterprise Linux ES version 2.1 | RedHat | * | |
| Red Hat Enterprise Linux WS version 2.1 | RedHat | * | |
| Red Hat Linux Advanced Workstation 2.1 | RedHat | * | |
| Lha | Ubuntu | dapper | * |
| Lha | Ubuntu | devel | * |
| Lha | Ubuntu | edgy | * |
| Lha | Ubuntu | feisty | * |