Vulnerabilities > CVE-2006-4116 - Buffer Overflow vulnerability in LHAZ LHA Long

047910
CVSS 5.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
high complexity
lhaz

Summary

Multiple stack-based buffer overflows in Lhaz before 1.32 allow user-assisted attackers to execute arbitrary code via a long filename in (1) an LHZ archive, when saving the filename during extraction; and (2) an LHZ archive with an invalid CRC checksum, when constructing an error message. This vulnerability is addressed in the following product release: Lhaz, Lhaz, 1.32

Vulnerable Configurations

Part Description Count
Application
Lhaz
1