CVE-2004-0235

Publication date 18 August 2004

Last updated 17 July 2025


Ubuntu priority

Description

Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containing filenames with (1) .. sequences or (2) absolute pathnames with double leading slashes ("//absolute/path").

Status

Package Ubuntu Release Status
lha 7.04 feisty
Fixed 1.14i-10
6.10 edgy
Fixed 1.14i-10
6.06 LTS dapper
Fixed 1.14i-10


Access our resources on patching vulnerabilities