CVE-2016-2347

Priority
Description
Integer underflow in the decode_level3_header function in
lib/lha_file_header.c in Lhasa before 0.3.1 allows remote attackers to
execute arbitrary code via a crafted archive.
Notes
Package
Source: lhasa (LP Ubuntu Debian)
Upstream:released (0.3.1-1)
Ubuntu 18.04 LTS:not-affected (0.3.1-1)
Ubuntu 20.04 LTS:not-affected (0.3.1-1)
Ubuntu 21.10:not-affected (0.3.1-1)
Ubuntu 22.04 LTS:not-affected (0.3.1-1)
Ubuntu 14.04 ESM:DNE (trusty was released [0.0.7-2+deb7u1ubuntu0.14.04.1])
Ubuntu 20.04 FIPS Compliant:not-affected (0.3.1-1)
Patches:
More Information

Updated: 2022-04-25 00:17:02 UTC (commit ecc1009cb19540b950de59270950018900f37f15)