ZeroHour

CVE-2016-2347

PoC
CVSS 3.0
7.8 high
EPSS
3%p87
Published
()
Modified
Description

Integer underflow in the decode_level3_header function in lib/lha_file_header.c in Lhasa before 0.3.1 allows remote attackers to execute arbitrary code via a crafted archive.

Vendors
opensusedebianlhasa project
Products
leap, opensuse, debian linux, lhasa
Weakness
CWE-190
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news