Full Disclosure mailing list archives
LHa repercussions: WinZip, WinRar, CommuniGate Pro McAfee plugin, blog
From: Ulf Härnhammar <Ulf.Harnhammar.9485 () student uu se>
Date: Wed, 5 May 2004 21:56:02 +0200
According to various sources on the net, the vulnerable LHa code has been used in other products. SecurityFocus says that WinZip and WinRar also are vulnerable to the LHa buffer overflows: http://www.securityfocus.com/bid/10243/info/ I have found a mailing list discussion about my LHa test archives crashing the McAfee plugin for CommuniGate Pro: http://mail.stalker.com/Lists/CGatePro/Message/61244.html I haven't had the time to verify either of those problems personally. There is also a blog entry about the security implications of everyone using the same LHa code (thanks to Kreiger for telling me about it): http://weblogs.asp.net/oldnewthing/archive/2004/05/04.aspx -- Ulf Harnhammar http://www.advogato.org/person/metaur/ _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- LHa repercussions: WinZip, WinRar, CommuniGate Pro McAfee plugin, blog Ulf Härnhammar (May 05)
- RE: LHa repercussions: WinZip, WinRar, CommuniGate Pro McAfee plugin, blog CommuniGate (May 06)
