Vulnonym.org

CVE-2008-2021 - Pricey Stretch

Description

Heap-based buffer overflow in Lhaplus before 1.57 allows remote attackers to execute arbitrary code via a long comment field in a ZOO archive.

Reference

http://jvn.jp/jp/JVN%2374468481/index.html http://www.fourteenforty.jp/research/advisory.cgi?FFRRA-20080428 http://www7a.biglobe.ne.jp/~schezo/ http://secunia.com/advisories/29972 http://www.securityfocus.com/bid/28953 http://www.vupen.com/english/advisories/2008/1369/references https://exchange.xforce.ibmcloud.com/vulnerabilities/42032