Описание
Heap-based buffer overflow in Lhaplus.exe in Lhaplus 1.52, and possibly earlier versions, allows remote attackers to execute arbitrary code via an LZH archive with a long header, as specified by the extendedHeaderSize.
Ссылки
- PatchVendor Advisory
- PatchVendor Advisory
- Exploit
- Patch
- Patch
- PatchVendor Advisory
- PatchVendor Advisory
- Exploit
- Patch
- Patch
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:lhaplus:lhaplus:1.52:*:*:*:*:*:*:*
EPSS
Процентиль: 92%
0.07706
Низкий
5.1 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
Heap-based buffer overflow in Lhaplus.exe in Lhaplus 1.52, and possibly earlier versions, allows remote attackers to execute arbitrary code via an LZH archive with a long header, as specified by the extendedHeaderSize.
EPSS
Процентиль: 92%
0.07706
Низкий
5.1 Medium
CVSS2
Дефекты
NVD-CWE-Other