PT-2007-4652 · Lhaca · Lhaca File Archiver

Publicado

2007-06-25

·

Atualizado

2017-07-29

·

CVE-2007-3375

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Lhaca File Archiver versions prior to 1.21
Description A stack-based buffer overflow issue allows user-assisted remote attackers to execute arbitrary code via a crafted LZH archive. This issue has been exploited by malware, such as Trojan.Lhdropper.
Recommendations For versions prior to 1.21, update to version 1.21 or later to resolve the issue. As a temporary workaround, consider avoiding the use of crafted LZH archives until the issue is resolved. Restrict access to untrusted LZH archives to minimize the risk of exploitation.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-3375

Produtos afetados

Lhaca File Archiver