Candidate: CVE-2016-2347 PublicDate: 2017-04-21 20:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2347 http://www.talosintel.com/reports/TALOS-2016-0095/ Description: Integer underflow in the decode_level3_header function in lib/lha_file_header.c in Lhasa before 0.3.1 allows remote attackers to execute arbitrary code via a crafted archive. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_lhasa: upstream_lhasa: released (0.3.1-1) precise_lhasa: DNE precise/esm_lhasa: DNE trusty_lhasa: released (0.0.7-2+deb7u1ubuntu0.14.04.1) trusty/esm_lhasa: DNE (trusty was released [0.0.7-2+deb7u1ubuntu0.14.04.1]) vivid/stable-phone-overlay_lhasa: DNE vivid/ubuntu-core_lhasa: DNE wily_lhasa: ignored (reached end-of-life) xenial_lhasa: ignored (end of standard support, was needed) yakkety_lhasa: not-affected (0.3.1-1) zesty_lhasa: not-affected (0.3.1-1) artful_lhasa: not-affected (0.3.1-1) bionic_lhasa: not-affected (0.3.1-1) cosmic_lhasa: not-affected (0.3.1-1) disco_lhasa: not-affected (0.3.1-1) eoan_lhasa: not-affected (0.3.1-1) focal_lhasa: not-affected (0.3.1-1) groovy_lhasa: not-affected (0.3.1-1) hirsute_lhasa: not-affected (0.3.1-1) impish_lhasa: not-affected (0.3.1-1) jammy_lhasa: not-affected (0.3.1-1) devel_lhasa: not-affected (0.3.1-1)