Bug 131948 - CAN-2004-0694, CAN-2004-0745, CAN-2004-0769, CAN-2004-0771 lha security flaws
CAN-2004-0694, CAN-2004-0745, CAN-2004-0769, CAN-2004-0771 lha security flaws
Status: CLOSED ERRATA
Product: Fedora
Classification: Fedora
Component: lha (Show other bugs)
2
All Linux
medium Severity medium
: ---
: ---
Assigned To: Ngo Than
https://rhn.redhat.com/errata/RHSA-20...
: Security
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2004-09-07 06:07 EDT by Bernhard Weisshuhn
Modified: 2007-11-30 17:10 EST (History)
0 users

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2004-09-07 09:01:42 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
dir_length bounds check from rhel3 (581 bytes, patch)
2004-09-07 06:19 EDT, Bernhard Weisshuhn
no flags Details | Diff
patch for extract_one and others from rhel (6.29 KB, patch)
2004-09-07 06:21 EDT, Bernhard Weisshuhn
no flags Details | Diff
New specfile to build fixed lha-1.14i-15 (3.22 KB, text/plain)
2004-09-07 06:22 EDT, Bernhard Weisshuhn
no flags Details

  None (edit)
Description Bernhard Weisshuhn 2004-09-07 06:07:12 EDT
The latest security patches for rhel #126740 have not made it into
fedora core yet, the included lha-1.14i-14 still looks vulnerable.
This entry shall serve as a reminder, since lha runs in a lot of
mail-scanners and may thus be remotely exploitable.

See https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=126740
http://rhn.redhat.com/errata/RHSA-2004-323.html
Comment 1 Bernhard Weisshuhn 2004-09-07 06:19:13 EDT
Created attachment 103533 [details]
dir_length bounds check from rhel3
Comment 2 Bernhard Weisshuhn 2004-09-07 06:21:06 EDT
Created attachment 103534 [details]
patch for extract_one and others from rhel
Comment 3 Bernhard Weisshuhn 2004-09-07 06:22:29 EDT
Created attachment 103535 [details]
New specfile to build fixed lha-1.14i-15
Comment 4 Ngo Than 2004-09-07 09:01:42 EDT
it's already built for fc1 and fc2. both still need to be signed and
pushed to download site.

Note You need to log in before you can comment on or make changes to this bug.