CVE detail
CVE-2004-0771 — CVE-2004-0771
Published 2004-11-23 · Modified 2026-06-16 · Vendor tsugio_okamoto · Product lha · Source nvd
UNKNOWN
severity
CVSS-derived band
0.1883
EPSS probability
exploitation probability, 30d
97.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Buffer overflow in the extract_one function from lhext.c in LHA may allow attackers to execute arbitrary code via a long w (working directory) command line option, a different issue than CVE-2004-0769. NOTE: this issue may be REJECTED if there are not any cases in which LHA is setuid or is otherwise used across security boundaries.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References