Gnu Sharutils vulnerabilities

5 known vulnerabilities affecting gnu/sharutils.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM1LOW1

Vulnerabilities

Page 1 of 1
CVE-2018-1000097HIGHCVSS 7.8v4.15.22018-03-13
CVE-2018-1000097 [HIGH] CWE-119 CVE-2018-1000097: Sharutils sharutils (unshar command) version 4.15.2 contains a Buffer Overflow vulnerability in Affe Sharutils sharutils (unshar command) version 4.15.2 contains a Buffer Overflow vulnerability in Affected component on the file unshar.c at line 75, function looks_like_c_code. Failure to perform checking of the buffer containing input line. that can result in Could lead to code execution. This attack appear to be exploitable via Victim have to run
nvd
CVE-2005-0990LOWCVSS 2.1v4.2.12005-05-02
CVE-2005-0990 [LOW] CVE-2005-0990: unshar (unshar.c) in sharutils 4.2.1 allows local users to overwrite arbitrary files via a symlink a unshar (unshar.c) in sharutils 4.2.1 allows local users to overwrite arbitrary files via a symlink attack on the unsh.X temporary file.
nvd
CVE-2004-1773HIGHCVSS 7.5v4.2v4.2.12004-12-31
CVE-2004-1773 [HIGH] CVE-2004-1773: Multiple buffer overflows in sharutils 4.2.1 and earlier may allow attackers to execute arbitrary co Multiple buffer overflows in sharutils 4.2.1 and earlier may allow attackers to execute arbitrary code via (1) long output from wc to shar, or (2) unknown vectors in unshar.
nvd
CVE-2004-1772MEDIUMCVSS 4.6v4.2v4.2.12004-12-31
CVE-2004-1772 [MEDIUM] CVE-2004-1772: Stack-based buffer overflow in shar in GNU sharutils 4.2.1 allows local users to execute arbitrary c Stack-based buffer overflow in shar in GNU sharutils 4.2.1 allows local users to execute arbitrary code via a long -o command line argument.
nvd
CVE-2002-0178HIGHCVSS 7.2v4.22002-05-29
CVE-2002-0178 [HIGH] CVE-2002-0178: uudecode, as available in the sharutils package before 4.2.1, does not check whether the filename of uudecode, as available in the sharutils package before 4.2.1, does not check whether the filename of the uudecoded file is a pipe or symbolic link, which could allow attackers to overwrite files or execute commands.
nvd