SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#871497

Lhaca buffer overflow vulnerability

Overview

The Lhaca archiving program contains a buffer overflow vulnerability that may allow an attacker to execute arbitrary code.

I. Description

LHA is an archive file format. LHA is used by the Lhaca compression utility.

A stack buffer overflow vulnerability exists in the Lhaca program. This vulnerability occurs due to insuffiecient bounds checking. Note that there are reports that this vulnerability is being publicly exploited.

II. Impact

A remote, unauthenticated attacker may be able to execute arbitrary code, or create a denial-of-service condition.

III. Solution

Upgrade

The vendor has released Lhaca version 1.23 to address this issue. Users are encouraged to upgrade as soon as possible.

Systems Affected

VendorStatusDate NotifiedDate Updated
3com, Inc.Unknown2007-07-052007-07-05
Aladdin Knowledge SystemsUnknown2007-07-052007-07-05
Apple Computer, Inc.Unknown2007-07-052007-07-05
BroNot Vulnerable2007-07-052007-07-13
Check Point Software TechnologiesUnknown2007-07-052007-07-05
Cisco Systems, Inc.Unknown2007-07-052007-07-05
Command Software SystemsNot Vulnerable2007-07-052007-07-24
Computer AssociatesNot Vulnerable2007-07-052009-01-16
Computer Associates eTrust Security ManagementNot Vulnerable2007-07-052009-01-16
Conectiva Inc.Unknown2007-07-052007-07-05
Cray Inc.Unknown2007-07-052007-07-05
CyberSoft, Inc.Unknown2007-07-052007-07-05
DataFellowsUnknown2007-07-052007-07-05
Debian GNU/LinuxNot Vulnerable2007-07-052007-07-31
EMC CorporationUnknown2007-07-052007-07-05
Engarde Secure LinuxUnknown2007-07-052007-07-05
Enterasys NetworksUnknown2007-07-052007-07-05
F-PROT by FRISK Software InternationalUnknown2007-07-052007-07-05
F-Secure CorporationNot Vulnerable2007-07-052007-07-17
F5 Networks, Inc.Unknown2007-07-052007-07-05
Fedora ProjectUnknown2007-07-052007-07-05
Finjan SoftwareUnknown2007-07-052007-07-05
Fortinet, Inc.Unknown2007-07-052007-07-05
FreeBSD, Inc.Unknown2007-07-052007-07-05
FujitsuUnknown2007-07-052007-07-05
Gentoo LinuxUnknown2007-07-052007-07-05
GFI Software, Inc.Unknown2007-07-052007-07-05
Hewlett-Packard CompanyUnknown2007-07-052007-07-05
HitachiUnknown2007-07-052007-07-05
IBM CorporationUnknown2007-07-052007-07-05
IBM Corporation (zseries)Unknown2007-07-052007-07-05
IBM eServerUnknown2007-07-052007-07-05
Immunix Communications, Inc.Unknown2007-07-052007-07-05
Ingrian Networks, Inc.Unknown2007-07-052007-07-05
Internet Security Systems, Inc.Not Vulnerable2007-07-052007-07-09
Juniper Networks, Inc.Unknown2007-07-052007-07-05
lhacaVulnerable2007-07-06
Mandriva, Inc.Unknown2007-07-052007-07-05
McAfeeUnknown2007-07-052007-07-05
MessageLabsUnknown2007-07-052007-07-05
Microsoft CorporationNot Vulnerable2007-07-052007-07-09
MontaVista Software, Inc.Unknown2007-07-052007-07-05
NEC CorporationUnknown2007-07-052007-07-05
NetBSDUnknown2007-07-052007-07-05
Nortel Networks, Inc.Unknown2007-07-052007-07-05
Novell, Inc.Unknown2007-07-052007-07-05
OpenBSDUnknown2007-07-052007-07-05
Openwall GNU/*/LinuxUnknown2007-07-052007-07-05
Proland Software, Inc.Unknown2007-07-052007-07-05
QNX, Software Systems, Inc.Unknown2007-07-052007-07-05
Red Hat, Inc.Not Vulnerable2007-07-052007-07-10
Silicon Graphics, Inc.Unknown2007-07-052007-07-05
Slackware Linux Inc.Unknown2007-07-052007-07-05
SnortNot Vulnerable2007-07-052007-07-06
Sony CorporationUnknown2007-07-052007-07-05
Sophos, Inc.Unknown2007-07-052007-07-05
SourcefireUnknown2007-07-052007-07-05
Sun Microsystems, Inc.Unknown2007-07-052007-07-05
SUSE LinuxUnknown2007-07-052007-07-05
Symantec, Inc.Unknown2007-07-052007-07-05
The SCO GroupUnknown2007-07-052007-07-05
TippingPoint, Technologies, Inc.Not Vulnerable2007-07-052007-07-06
Trend MicroUnknown2007-07-052007-07-05
Trustix Secure LinuxUnknown2007-07-052007-07-05
TurbolinuxUnknown2007-07-052007-07-05
UbuntuUnknown2007-07-052007-07-05
UnisysUnknown2007-07-052007-07-05
Wind River Systems, Inc.Unknown2007-07-052007-07-05

References


http://park8.wakwak.com/~app/Lhaca/
http://www.securityfocus.com/bid/24604
http://www.symantec.com/enterprise/security_response/weblog/2007/06/beware_of_lzh.html
http://vuln.sg/lhaca121-en.html
http://64.233.179.104/translate_c?hl=en&u=http://park8.wakwak.com/~app/Lhaca/overflow.html&prev=/search%3Fq%3Dlhaca%26hl%3Den%26client%3Dfirefox-a%26rls%3Dorg.mozilla:en-US:official%26hs%3DirC
http://en.wikipedia.org/wiki/LHA_(software)
http://secunia.com/advisories/25826/
http://oku.edu.mie-u.ac.jp/~okumura/compression/history.html

Credit

Thanks to Lhaca, Symantec, and Vuln.sg for information that was used in this report.

This document was written by Ryan Giobbi.

Other Information

Date Public:2007-06-25
Date First Published:2007-07-06
Date Last Updated:2009-01-16
CERT Advisory: 
CVE-ID(s):CVE-2007-3375
NVD-ID(s):CVE-2007-3375
US-CERT Technical Alerts: 
Metric:4.02
Document Revision:8

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2007 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader