CVE-2016-2347 describes an integer underflow vulnerability in the Lhasa decompression library (specifically in lib/lha_file_header.c's decode_level3_header function) before version 0.3.1, affecting products like Debian and openSUSE. This flaw allows remote attackers to execute arbitrary code through a crafted archive. With a CVSS v3 score of 7.8 (HIGH), it has a local attack vector, low attack complexity, and high impacts on confidentiality, integrity, and availability, requiring user interaction. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog, though it garnered some community discussion and media coverage at the time of discovery.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
42.1CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:* | ||
13.2CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
<= 0.3.0CPE matchmatch criteria | cpe:2.3:a:lhasa_project:lhasa:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.