CVE-2016-2347
published 2017-04-21CVE-2016-2347: Integer underflow in the decode_level3_header function in lib/lha_file_header.c in Lhasa before 0.3.1 allows remote attackers to execute arbitrary code via a…
PriorityP340high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
3.23%
86.8th percentile
Integer underflow in the decode_level3_header function in lib/lha_file_header.c in Lhasa before 0.3.1 allows remote attackers to execute arbitrary code via a crafted archive.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | lhasa | < lhasa 0.3.1-1 (bookworm) | lhasa 0.3.1-1 (bookworm) |
| lhasa_project | lhasa | <= 0.3.0 | — |
| lhasa_project | lhasa | >= 0 < 0.3.1-1 | 0.3.1-1 |
| lhasa_project | lhasa | >= 0 < 0.3.1-1 | 0.3.1-1 |
| lhasa_project | lhasa | >= 0 < 0.3.1-1 | 0.3.1-1 |
| lhasa_project | lhasa | >= 0 < 0.3.1-1 | 0.3.1-1 |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9xgv-x5fv-g6vp: Integer underflow in the decode_level3_header function in lib/lha_file_header
ghsa_unreviewed·2022-05-14
CVE-2016-2347 [HIGH] CWE-190 GHSA-9xgv-x5fv-g6vp: Integer underflow in the decode_level3_header function in lib/lha_file_header
Integer underflow in the decode_level3_header function in lib/lha_file_header.c in Lhasa before 0.3.1 allows remote attackers to execute arbitrary code via a crafted archive.
OSV
CVE-2016-2347: Integer underflow in the decode_level3_header function in lib/lha_file_header
osv·2017-04-21·CVSS 7.8
CVE-2016-2347 [HIGH] CVE-2016-2347: Integer underflow in the decode_level3_header function in lib/lha_file_header
Integer underflow in the decode_level3_header function in lib/lha_file_header.c in Lhasa before 0.3.1 allows remote attackers to execute arbitrary code via a crafted archive.
Debian
CVE-2016-2347: lhasa - Integer underflow in the decode_level3_header function in lib/lha_file_header.c ...
vendor_debian·2016·CVSS 7.8
CVE-2016-2347 [HIGH] CVE-2016-2347: lhasa - Integer underflow in the decode_level3_header function in lib/lha_file_header.c ...
Integer underflow in the decode_level3_header function in lib/lha_file_header.c in Lhasa before 0.3.1 allows remote attackers to execute arbitrary code via a crafted archive.
Scope: local
bookworm: resolved (fixed in 0.3.1-1)
bullseye: resolved (fixed in 0.3.1-1)
forky: resolved (fixed in 0.3.1-1)
sid: resolved (fixed in 0.3.1-1)
trixie: resolved (fixed in 0.3.1-1)
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Lhasa Integer Underflow Exploit
blogs_talos·2016-03-31·CVSS 7.8
CVE-2016-2347 [HIGH] Vulnerability Spotlight: Lhasa Integer Underflow Exploit
Vulnerability discovered by Marcin Noga of Cisco Talos.
Talos is disclosing the discovery of vulnerability TALOS-2016-0095 / CVE-2016-2347 in the Lhasa LZH/LHA decompression tool and library. This vulnerability is due to an integer underflow condition. The software verifies that header values are not too large, but does not check for a too small header length. Decompressing a LHA or LZH file containing an under-value header size leads to the decompression software allocating a pointer to point to released memory on the heap. An attacker controlling the length and content of such a file can use the vulnerability to overwrite the heap with arbitrary code.
An evident attack vector is to trick users into opening malicious files and exploiting the vulnerability to execute malicious code on th
Talos
Vulnerability Spotlight: Lhasa Integer Underflow Exploit
blogs_talos·2016-03-31·CVSS 7.8
CVE-2016-2347 [HIGH] Vulnerability Spotlight: Lhasa Integer Underflow Exploit
## Vulnerability Spotlight: Lhasa Integer Underflow Exploit
Vulnerability discovered by Marcin Noga of Cisco Talos.
Talos is disclosing the discovery of vulnerability TALOS-2016-0095 / CVE-2016-2347 in the Lhasa LZH/LHA decompression tool and library. This vulnerability is due to an integer underflow condition. The software verifies that header values are not too large, but does not check for a too small header length. Decompressing a LHA or LZH file containing an under-value header size leads to the decompression software allocating a pointer to point to released memory on the heap. An attacker controlling the length and content of such a file can use the vulnerability to overwrite the heap with arbitrary code.
An evident attack vector is to trick users into opening malicious files and
http://lists.opensuse.org/opensuse-updates/2016-04/msg00038.htmlhttp://lists.opensuse.org/opensuse-updates/2016-04/msg00039.htmlhttp://www.debian.org/security/2016/dsa-3540http://www.talosintelligence.com/reports/TALOS-2016-0095/https://github.com/fragglet/lhasa/commit/6fcdb8f1f538b9d63e63a5fa199c5514a15d4564https://github.com/fragglet/lhasa/releases/tag/v0.3.1http://lists.opensuse.org/opensuse-updates/2016-04/msg00038.htmlhttp://lists.opensuse.org/opensuse-updates/2016-04/msg00039.htmlhttp://www.debian.org/security/2016/dsa-3540http://www.talosintelligence.com/reports/TALOS-2016-0095/https://github.com/fragglet/lhasa/commit/6fcdb8f1f538b9d63e63a5fa199c5514a15d4564https://github.com/fragglet/lhasa/releases/tag/v0.3.1
2017-04-21
Published