CVE-2004-0771 describes a critical buffer overflow vulnerability in the extract_one function of LHA, specifically affecting tsugio_okamoto lha versions. This flaw allows attackers to execute arbitrary code by providing an excessively long working directory (w) command-line option. With a CVSS score of 10.0, this vulnerability is highly severe, requiring no authentication or complex attack vectors, and potentially leading to complete compromise of confidentiality, integrity, and availability. While not listed on the KEV catalog and lacking social media or media coverage, exploit code is publicly available on ExploitDB, indicating a potential for exploitation despite no evidence of active widespread attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.14CPE matchmatch criteria | cpe:2.3:a:tsugio_okamoto:lha:1.14:*:*:*:*:*:*:* | ||
1.15CPE matchmatch criteria | cpe:2.3:a:tsugio_okamoto:lha:1.15:*:*:*:*:*:*:* | ||
1.17CPE matchmatch criteria | cpe:2.3:a:tsugio_okamoto:lha:1.17:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.