This script is Copyright (C) 2006-2016 Tenable Network Security, Inc.
The remote Gentoo host is missing one or more security-related
The remote host is affected by the vulnerability described in GLSA-200611-24
(LHa: Multiple vulnerabilities)
Tavis Ormandy of the Google Security Team discovered several
vulnerabilities in the LZH decompression component used by LHa. The
make_table function of unlzh.c contains an array index error and a
buffer overflow vulnerability. The build_tree function of unpack.c
contains a buffer underflow vulnerability. Additionally, unlzh.c
contains a code that could run in an infinite loop.
By enticing a user to uncompress a specially crafted archive, a remote
attacker could cause a Denial of Service by CPU consumption or execute
arbitrary code with the rights of the user running the application.
There is no known workaround at this time.
See also :
All LHa users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=app-arch/lha-114i-r6'
Risk factor :
High / CVSS Base Score : 7.5
CVSS Temporal Score : 6.1
Public Exploit Available : false
Family: Gentoo Local Security Checks
Nessus Plugin ID: 23746 (gentoo_GLSA-200611-24.nasl)
Get Nessus Professional to scan unlimited IPs, run compliance checks & moreBuy Nessus Professional Now