CVE-2004-0235

Description

From CVE.org

Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containing filenames with (1) .. sequences or (2) absolute pathnames with double leading slashes ("//absolute/path").

Acknowledgements

Red Hat would like to thank Ulf Härnhammar for reporting this issue.

Frequently Asked Questions

Want to get errata notifications? Sign up here.