| [Japanese] | 
| JVNDB-2008-000022 | 
| Lhaplus buffer overflow vulnerability | 
|
| 
 
Lhaplus, file compression/decompression software supporting multiple compression file formats, contains a buffer overflow vulnerability.
 Lhaplus, file compression/decompression software supporting multiple compression file formats, contains a buffer overflow vulnerability. If a user decompresses a specially crafted file, an attacker could execute arbitrary code with the privilege of the user. This vulnerability is different from JVN#82610488 and JVN#70734805.
 
 Yuji Ukai of Fourteenforty Research Institute, Inc. reported this vulnerability to IPA.
 JPCERT/CC coordinated with the vendor under Information Security Early Warning Partnership.
 | 
|
| 
 
  CVSS V2 Severity:Base Metrics 6.8 (Medium) [IPA Score]
 
    Access Vector: NetworkAccess Complexity: LowAuthentication: NoneConfidentiality Impact: PartialIntegrity Impact: PartialAvailability Impact: Partial 
  
 | 
|
| 
 
	
 | 
| 
 
	Schezo
	
		Lhaplus Version 1.56 and eariler | 
| 
 
	
 | 
|
| 
 
An attacker could execute arbitrary code with the privilege of the user who decompressed the file.
 | 
|
| 
 
[Update the Software]Update to the latest version according to the information provided by the vendor.
 For more information, refer to the vendor's website.
 | 
|
| 
 
	Schezo
	
 | 
|
| 
 
	Buffer Errors(CWE-119) [NVD Evaluation] | 
|
| 
 
	CVE-2008-2021  | 
|
| 
 
	JVN : JVN#74468481 National Vulnerability Database (NVD) : CVE-2008-2021 IPA SECURITY ALERTS : Security Alert for Lhaplus Vulnerability Secunia Advisory : SA29972 SecurityFocus : 28953 ISS X-Force Database : 42032 FrSIRT Advisories : FrSIRT/ADV-2008-1369  | 
|
| 
 
	[2008/05/21]Web page published
 
 |