CVE-2004-0235

6 documents6 sources
Severity
6.4MEDIUM
EPSS
10.5%
top 6.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 18
Latest updateApr 29

Description

Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containing filenames with (1) .. sequences or (2) absolute pathnames with double leading slashes ("//absolute/path").

CVSS vector

AV:N/AC:L/C:P/I:P/A:NExploitability: 10.0 | Impact: 4.9

Affected Packages13 packages

NVDredhat/lha1.14i-9
NVDsgi/propack2.4, 3.0+1
NVDrarlab/winrar3.20
NVDwinzip/winzip9.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-v492-qprp-rvhr: Multiple directory traversal vulnerabilities in LHA 12022-04-29
CVEList
CVE-2004-0235: Multiple directory traversal vulnerabilities in LHA 12004-05-05

💥Exploits & PoCs

1
Exploit-DB
LHA 1.x - Remote Buffer Overflow / Directory Traversal2004-04-30

📋Vendor Advisories

1
Red Hat
security flaw2004-05-01

💬Community

1
Bugzilla
CVE-2004-0235 security flaw2018-08-16
CVE-2004-0235 (MEDIUM CVSS 6.4) | Multiple directory traversal vulner | cvebase.io