PT-2004-1073 · Gnu+1 · Sharutils+1
Published
2004-12-31
·
Updated
2017-10-11
·
CVE-2004-1773
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
sharutils versions 4.2.1 and earlier
Description
The issue concerns multiple buffer overflows in the sharutils package, which can be exploited to execute arbitrary code. This can be achieved via long output from
wc to shar, or through unknown vectors in unshar. Exploitation of these issues may lead to a breach of confidentiality, integrity, and availability of protected information, and can be performed remotely.Recommendations
For sharutils versions 4.2.1 and earlier, consider updating to a newer version that addresses these buffer overflows.
As a temporary workaround, consider restricting the use of
shar and unshar until a patch is available.
Avoid using wc with long output to shar in the affected versions until the issue is resolved.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Hat
Sharutils