SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2004-0235

Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containing filenames with (1) .. sequences or (2) absolute pathnames with double leading slashes…

MEDIUM 6.4EPSS 4.12%

Does this matter?

Lower severity and a low EPSS score (4.12%). Track it; it rarely justifies an emergency change on its own.

Description

Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containing filenames with (1) .. sequences or (2) absolute pathnames with double leading slashes ("//absolute/path").

CVSS 2.0
6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
EPSS
4.12% probability · 90th percentile
CISA KEV
Not listed
Affected
clearswift/mailsweeper · f-secure/f-secure anti-virus · f-secure/f-secure for firewalls · f-secure/f-secure internet security · f-secure/f-secure personal express · f-secure/internet gatekeeper · rarlab/winrar · redhat/lha · sgi/propack · stalker/cgpmcafee · tsugio okamoto/lha · winzip/winzip · redhat/fedora core
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.