Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Koji Ando

Researcher fromLAC Co., Ltd.
#51429of 53,633
4.3Total CVSS
Vulnerabilities · 1
PT-2018-7105
4.3
2018-01-12
Lhaplus · Lhaplus · CVE-2017-2158
Name of the Vulnerable Software and Affected Versions: Lhaplus versions 1.73 and earlier Description: The issue arises from improper verification when expanding ZIP64 archives, potentially leading to the extraction of unintended contents from a specially crafted ZIP64 archive. Recommendations: For Lhaplus versions 1.73 and earlier, update to a version later than 1.73 to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.