漏洞信息详情
LHA多个代码执行漏洞
漏洞简介
LHA 1.14及其早期版本存在漏洞。攻击者可以借助名称带有shell元字符的目录执行任意命令。
漏洞公告
RedHat has released an advisory (RHSA-2004:323-09) to address these issues. Please see the advisory in Web references for more information. RedHat has released an advisory (RHSA-2004:440-04) along with fixes to address these issues for RedHat Enterprise Linux operating systems. Please see the referenced advisory for further information. RedHat Fedora has released advisories FEDORA-2004-294 and FEDORA-2004-295 dealing with these issues for their Core 1 and Core 2 products. Please see the referenced advisories for more information. Gentoo has released advisory GLSA 200409-13 dealing with these issues. All LHa users should upgrade to the latest stable version with the following commands: # emerge sync # emerge -pv ">=app-arch/lha-114i-r4" # emerge ">=app-arch/lha-114i-r4" Please see the referenced Gentoo advisory for more information. The Fedora Legacy project has released advisory FLSA:1833 along with fixes to address this issue in RedHat Linux 7.3. Please see the referenced advisory for further information. Mr. S.K. LHA 1.14
- Fedora lha-1.14i-12.2.i386.rpmRedHat Fedora Core 1 http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
- Fedora lha-1.14i-12.2.x86_64.rpmRedHat Fedora Core 1 http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
- Fedora lha-1.14i-14.1.i386.rpmRedHat Fedora Core 2 http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
- Fedora lha-1.14i-14.1.x86_64.rpmRedHat Fedora Core 2 http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
- Fedora lha-debuginfo-1.14i-12.2.i386.rpmRedHat Fedora Core 1 http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
- Fedora lha-debuginfo-1.14i-12.2.x86_64.rpmRedHat Fedora Core 1 http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
- Fedora lha-debuginfo-1.14i-14.1.i386.rpmRedHat Fedora Core 2 http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
- Fedora lha-debuginfo-1.14i-14.1.x86_64.rpmRedHat Fedora Core 2 http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
- RedHat lha-1.14i-4.7.3.3.legacy.i386.rpmRedHat Linux 7.3 http://download.fedoralegacy.org/redhat/7.3/updates/i386/lha-1.14i-4.7 .3.3.legacy.i386.rpm
- RedHat lha-1.14i-9.4.legacy.i386.rpmRedHat Linux 9 http://download.fedoralegacy.org/redhat/9/updates/i386/lha-1.14i-9.4.l egacy.i386.rpm
参考网址
来源: XF 名称: lha-metacharacter-command-execution(17198) 链接:http://xforce.iss.net/xforce/xfdb/17198 来源: REDHAT 名称: RHSA-2004:440 链接:http://www.redhat.com/support/errata/RHSA-2004-440.html 来源: FEDORA 名称: FLSA:1833 链接:https://bugzilla.fedora.us/show_bug.cgi?id=1833 来源: GENTOO 名称: GLSA-200409-13 链接:http://www.gentoo.org/security/en/glsa/glsa-200409-13.xml 来源: OVAL 名称: oval:org.mitre.oval:def:11088 链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11088
受影响实体
- Tsugio_okamoto Lha:1.14<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...