CVE-2004-0235
Last modified
CVE-2004-0235 is a vulnerability of currently unknown severity. Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containing filenames with (1) .. sequences or (2) absolute pathnames with double leading slashes ("//absolute/path").. EPSS estimates a 4.12% chance of exploitation in the next 30 days.
Description
Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containing filenames with (1) .. sequences or (2) absolute pathnames with double leading slashes ("//absolute/path").
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Clearswift | Mailsweeper | 4.0 |
| Clearswift | Mailsweeper | 4.1 |
| Clearswift | Mailsweeper | 4.2 |
| Clearswift | Mailsweeper | 4.3 |
| Clearswift | Mailsweeper | 4.3.3 |
| Clearswift | Mailsweeper | 4.3.4 |
| Clearswift | Mailsweeper | 4.3.5 |
| Clearswift | Mailsweeper | 4.3.6 |
| Clearswift | Mailsweeper | 4.3.6_sp1 |
| Clearswift | Mailsweeper | 4.3.7 |
| Clearswift | Mailsweeper | 4.3.8 |
| Clearswift | Mailsweeper | 4.3.10 |
| Clearswift | Mailsweeper | 4.3.11 |
| Clearswift | Mailsweeper | 4.3.13 |
| F-Secure | F-Secure Anti-Virus | 4.51 |
| F-Secure | F-Secure Anti-Virus | 4.52 |
| F-Secure | F-Secure Anti-Virus | 4.60 |
| F-Secure | F-Secure Anti-Virus | 5.5 |
| F-Secure | F-Secure Anti-Virus | 5.41 |
| F-Secure | F-Secure Anti-Virus | 5.42 |
| F-Secure | F-Secure Anti-Virus | 5.52 |
| F-Secure | F-Secure Anti-Virus | 6.21 |
| F-Secure | F-Secure Anti-Virus | 2003 |
| F-Secure | F-Secure Anti-Virus | 2004 |
| F-Secure | F-Secure For Firewalls | 6.20 |
| F-Secure | F-Secure Internet Security | 2003 |
| F-Secure | F-Secure Internet Security | 2004 |
| F-Secure | F-Secure Personal Express | 4.5 |
| F-Secure | F-Secure Personal Express | 4.6 |
| F-Secure | F-Secure Personal Express | 4.7 |
| F-Secure | Internet Gatekeeper | 6.31 |
| F-Secure | Internet Gatekeeper | 6.32 |
| Rarlab | Winrar | 3.20 |
| Redhat | Lha | 1.14i-9 |
| Sgi | Propack | 2.4 |
| Sgi | Propack | 3.0 |
| Stalker | Cgpmcafee | 3.2 |
| Tsugio Okamoto | Lha | 1.14 |
| Tsugio Okamoto | Lha | 1.15 |
| Tsugio Okamoto | Lha | 1.17 |
| Winzip | Winzip | 9.0 |
| Redhat | Fedora Core | core_1.0 |
References
- http://www.securityfocus.com/bid/10243Exploit, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/10243Exploit, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-0235?
How severe is CVE-2004-0235?
How do I fix CVE-2004-0235?
Are you affected by CVE-2004-0235?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
