PT-2018-7105 · Lhaplus · Lhaplus
Koji Ando
·
Published
2018-01-12
·
Updated
2018-02-02
·
CVE-2017-2158
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Lhaplus versions 1.73 and earlier
Description:
The issue arises from improper verification when expanding ZIP64 archives, potentially leading to the extraction of unintended contents from a specially crafted ZIP64 archive.
Recommendations:
For Lhaplus versions 1.73 and earlier, update to a version later than 1.73 to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lhaplus