CVE-2006-4116

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/08/2006
Last modified:
03/04/2025

Description

Multiple stack-based buffer overflows in Lhaz before 1.32 allow user-assisted attackers to execute arbitrary code via a long filename in (1) an LHZ archive, when saving the filename during extraction; and (2) an LHZ archive with an invalid CRC checksum, when constructing an error message.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lhaz:lhaz:*:*:*:*:*:*:*:* 1.31 (including)