Integer underflow in header.c in lha allows remote attackers to have unspecified impact via a large header size value for the (1) level0 or (2) level1 header in a lha archive, which triggers a buffer overflow.
The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2016/01/18/8 | third party advisory mailing list |
http://www.openwall.com/lists/oss-security/2016/01/18/3 | third party advisory mailing list |
https://security.gentoo.org/glsa/202007-42 | vendor advisory |