10

CVE-2004-0234

Exploit
Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local users to execute arbitrary code via long directory or file names in an LHA archive, which triggers the overflow when testing or extracting the archive.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Clearswift ≫ Mailsweeper Version 4.0
Clearswift ≫ Mailsweeper Version 4.1
Clearswift ≫ Mailsweeper Version 4.2
Clearswift ≫ Mailsweeper Version 4.3
Clearswift ≫ Mailsweeper Version 4.3.3
Clearswift ≫ Mailsweeper Version 4.3.4
Clearswift ≫ Mailsweeper Version 4.3.5
Clearswift ≫ Mailsweeper Version 4.3.6
Clearswift ≫ Mailsweeper Version 4.3.6_sp1
Clearswift ≫ Mailsweeper Version 4.3.7
Clearswift ≫ Mailsweeper Version 4.3.8
Clearswift ≫ Mailsweeper Version 4.3.10
Clearswift ≫ Mailsweeper Version 4.3.11
Clearswift ≫ Mailsweeper Version 4.3.13
F-secure ≫ F-secure Anti-virus Version 4.51 Edition linux_gateways
F-secure ≫ F-secure Anti-virus Version 4.51 Edition linux_servers
F-secure ≫ F-secure Anti-virus Version 4.51 Edition linux_workstations
F-secure ≫ F-secure Anti-virus Version 4.52 Edition linux_gateways
F-secure ≫ F-secure Anti-virus Version 4.52 Edition linux_servers
F-secure ≫ F-secure Anti-virus Version 4.52 Edition linux_workstations
F-secure ≫ F-secure Anti-virus Version 4.60 Edition samba_servers
F-secure ≫ F-secure Anti-virus Version 5.5 Edition client_security
F-secure ≫ F-secure Anti-virus Version 5.41 Edition mimesweeper
F-secure ≫ F-secure Anti-virus Version 5.41 Edition windows_servers
F-secure ≫ F-secure Anti-virus Version 5.41 Edition workstations
F-secure ≫ F-secure Anti-virus Version 5.42 Edition mimesweeper
F-secure ≫ F-secure Anti-virus Version 5.42 Edition windows_servers
F-secure ≫ F-secure Anti-virus Version 5.42 Edition workstations
F-secure ≫ F-secure Anti-virus Version 5.52 Edition client_security
F-secure ≫ F-secure Anti-virus Version 6.21 Edition ms_exchange
F-secure ≫ F-secure Anti-virus Version 2003
F-secure ≫ F-secure Anti-virus Version 2004
F-secure ≫ F-secure For Firewalls Version 6.20
F-secure ≫ Internet Gatekeeper Version 6.31
F-secure ≫ Internet Gatekeeper Version 6.32
RARLAB ≫ WinRAR Version 3.20
Redhat ≫ Lha Version 1.14i-9 Edition i386
Sgi ≫ Propack Version 2.4
Sgi ≫ Propack Version 3.0
Stalker ≫ Cgpmcafee Version 3.2
Tsugio Okamoto ≫ Lha Version 1.14
Tsugio Okamoto ≫ Lha Version 1.15
Tsugio Okamoto ≫ Lha Version 1.17
Winzip ≫ Winzip Version 9.0
Redhat ≫ Fedora Core Version core_1.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 10.26% 0.951
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://archives.neohapsis.com/archives/bugtraq/2006-04/0059.html
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000840
http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/020776.html
http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/020778.html
http://marc.info/?l=bugtraq&m=108422737918885&w=2
http://secunia.com/advisories/19514
Vendor Advisory
http://security.gentoo.org/glsa/glsa-200405-02.xml
http://securitytracker.com/id?1015866
http://www.debian.org/security/2004/dsa-515
http://www.guay-leroux.com/projects/barracuda-advisory-LHA.txt
http://www.osvdb.org/5753
http://www.osvdb.org/5754
http://www.redhat.com/archives/fedora-announce-list/2004-May/msg00005.html
http://www.redhat.com/support/errata/RHSA-2004-178.html
http://www.redhat.com/support/errata/RHSA-2004-179.html
http://www.securityfocus.com/bid/10243
Patch
Vendor Advisory
Exploit
http://www.vupen.com/english/advisories/2006/1220
Vendor Advisory
https://bugzilla.fedora.us/show_bug.cgi?id=1833
https://exchange.xforce.ibmcloud.com/vulnerabilities/16012
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A977
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9881