search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Lhaca buffer overflow vulnerability

Vulnerability Note VU#871497

Original Release Date: 2007-07-06 | Last Revised: 2009-01-16

Overview

The Lhaca archiving program contains a buffer overflow vulnerability that may allow an attacker to execute arbitrary code.

Description

LHA is an archive file format. LHA is used by the Lhaca compression utility.

A stack buffer overflow vulnerability exists in the Lhaca program. This vulnerability occurs due to insuffiecient bounds checking. Note that there are reports that this vulnerability is being publicly exploited.

Impact

A remote, unauthenticated attacker may be able to execute arbitrary code, or create a denial-of-service condition.

Solution

Upgrade
The vendor has released Lhaca version 1.23 to address this issue. Users are encouraged to upgrade as soon as possible.

Vendor Information

871497
 

View all 68 vendors View less vendors


CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

Thanks to Lhaca, Symantec, and Vuln.sg for information that was used in this report.

This document was written by Ryan Giobbi.

Other Information

CVE IDs: CVE-2007-3375
Severity Metric: 4.02
Date Public: 2007-06-25
Date First Published: 2007-07-06
Date Last Updated: 2009-01-16 15:15 UTC
Document Revision: 8

Sponsored by CISA.