PT-2004-1073 · Gnu+1 · Sharutils+1

Published

2004-12-31

·

Updated

2017-10-11

·

CVE-2004-1773

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions sharutils versions 4.2.1 and earlier
Description The issue concerns multiple buffer overflows in the sharutils package, which can be exploited to execute arbitrary code. This can be achieved via long output from wc to shar, or through unknown vectors in unshar. Exploitation of these issues may lead to a breach of confidentiality, integrity, and availability of protected information, and can be performed remotely.
Recommendations For sharutils versions 4.2.1 and earlier, consider updating to a newer version that addresses these buffer overflows. As a temporary workaround, consider restricting the use of shar and unshar until a patch is available. Avoid using wc with long output to shar in the affected versions until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-06532
CVE-2004-1773
RHSA-2005:377
RHSA-2005_377

Affected Products

Red Hat
Sharutils