Lhasa Integer Overflow Vulnerability (CVE-2016-2347)
Lhasa Integer Overflow Vulnerability (CVE-2016-2347)
Release date:
Updated on:
Affected Systems:
Lhasa 0.3.0
Lhasa 0.0.7
Description:
CVE (CAN) ID: CVE-2016-2347
Lhasa is an open-source tool and library for parsing and extracting LHA (. lzh) documents.
Lhasa v0.3.0 and earlier versions have the integer overflow vulnerability, which can cause arbitrary code execution. This vulnerability occurs because Lhasa checks whether the header value is too large, but does not verify whether the length of the ticket header is too small.
<* Source: Marcin 'icewall' Noga
*>
Suggestion:
Vendor patch:
Lhasa
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://github.com/fragglet/lhasa/releases
This article permanently updates the link address: