10

CVE-2004-0234

Exploit

Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local users to execute arbitrary code via long directory or file names in an LHA archive, which triggers the overflow when testing or extracting the archive.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ClearswiftMailsweeper Version4.0
ClearswiftMailsweeper Version4.1
ClearswiftMailsweeper Version4.2
ClearswiftMailsweeper Version4.3
ClearswiftMailsweeper Version4.3.3
ClearswiftMailsweeper Version4.3.4
ClearswiftMailsweeper Version4.3.5
ClearswiftMailsweeper Version4.3.6
ClearswiftMailsweeper Version4.3.6_sp1
ClearswiftMailsweeper Version4.3.7
ClearswiftMailsweeper Version4.3.8
ClearswiftMailsweeper Version4.3.10
ClearswiftMailsweeper Version4.3.11
ClearswiftMailsweeper Version4.3.13
F-secureF-secure Anti-virus Version4.51 Editionlinux_gateways
F-secureF-secure Anti-virus Version4.51 Editionlinux_servers
F-secureF-secure Anti-virus Version4.51 Editionlinux_workstations
F-secureF-secure Anti-virus Version4.52 Editionlinux_gateways
F-secureF-secure Anti-virus Version4.52 Editionlinux_servers
F-secureF-secure Anti-virus Version4.52 Editionlinux_workstations
F-secureF-secure Anti-virus Version4.60 Editionsamba_servers
F-secureF-secure Anti-virus Version5.5 Editionclient_security
F-secureF-secure Anti-virus Version5.41 Editionmimesweeper
F-secureF-secure Anti-virus Version5.41 Editionwindows_servers
F-secureF-secure Anti-virus Version5.41 Editionworkstations
F-secureF-secure Anti-virus Version5.42 Editionmimesweeper
F-secureF-secure Anti-virus Version5.42 Editionwindows_servers
F-secureF-secure Anti-virus Version5.42 Editionworkstations
F-secureF-secure Anti-virus Version5.52 Editionclient_security
F-secureF-secure Anti-virus Version6.21 Editionms_exchange
F-secureF-secure Anti-virus Version2003
F-secureF-secure Anti-virus Version2004
F-secureInternet Gatekeeper Version6.31
F-secureInternet Gatekeeper Version6.32
RARLABWinRAR Version3.20
RedhatLha Version1.14i-9 Editioni386
SgiPropack Version2.4
SgiPropack Version3.0
StalkerCgpmcafee Version3.2
Tsugio OkamotoLha Version1.14
Tsugio OkamotoLha Version1.15
Tsugio OkamotoLha Version1.17
WinzipWinzip Version9.0
RedhatFedora Core Versioncore_1.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.48% 0.915
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.