Published:2018/01/11 Last Updated:2018/01/11
JVN#57842148
Lhaplus vulnerable to improper verification when expanding ZIP64 archives
Overview
Lhaplus does not treat ZIP64 archives properly when expanding.
Products Affected
- Lhaplus Version 1.73 and earlier
Description
Lhaplus is file compression/decompression software. Lhaplus does not treat ZIP64 archives properly when expanding.
Impact
An unintended content may be extracted from a crafted ZIP64 archive.
Solution
Update the Software
Update to the latest version according to the information provided by the developer.
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
CVSS v3
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Base Score:
3.3
CVSS v2
AV:N/AC:M/Au:N/C:N/I:P/A:N
Base Score:
4.3
Credit
Koji Ando of LAC Co., Ltd. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Other Information
JPCERT Alert |
|
JPCERT Reports |
|
CERT Advisory |
|
CPNI Advisory |
|
TRnotes |
|
CVE |
CVE-2017-2158 |
JVN iPedia |
JVNDB-2018-000001 |