Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Lhaplus ARJ Archive Long Filename Handling Buffer Overflow Vulnerability

Lhaplus is prone to a heap-based buffer-overflow vulnerability when handling ARJ archives with overly long filenames.

A successful attack can allow a remote attacker to corrupt process memory by triggering an overflow condition when Lhaplus reads an inordinately long ARJ archive filename.

This vulnerability reportedly affects Lhaplus 1.53 (Japanese); previous versions may also be vulnerable.







 

Privacy Statement
Copyright 2008, SecurityFocus