Vulnerability Name:

CVE-2016-1925 (CCN-110081)

Assigned:2016-01-18
Published:2016-01-18
Updated:2020-07-27
Summary:Integer underflow in header.c in lha allows remote attackers to have unspecified impact via a large header size value for the (1) level0 or (2) level1 header in a lha archive, which triggers a buffer overflow.
CVSS v3 Severity:9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
6.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-191
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2016-1925

Source: CCN
Type: Lha for Windows - SourceForge Web site
Lha for Windows

Source: CCN
Type: oss-sec Mailing List, Mon, 18 Jan 2016 13:54:41 -0500 (EST)
Re: Buffer Overflow in lha compression utility

Source: MLIST
Type: Mailing List, Third Party Advisory
[oss-security] 20160118 Buffer Overflow in lha compression utility

Source: MLIST
Type: Mailing List, Third Party Advisory
[oss-security] 20160118 Re: Buffer Overflow in lha compression utility

Source: XF
Type: UNKNOWN
lha-cve20161925-bo(110081)

Source: CCN
Type: OSDN Web site
LHa for Unix

Source: GENTOO
Type: UNKNOWN
GLSA-202007-42

Vulnerable Configuration:Configuration 1:
  • cpe:/a:lha_for_unix_project:lha_for_unix:-:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20161925
    V
    CVE-2016-1925
    2022-05-20
    oval:org.opensuse.security:def:34677
    P
    Security update for libvirt (Important)
    2022-01-05
    oval:org.opensuse.security:def:34053
    P
    Security update for libsndfile (Important)
    2022-01-05
    oval:org.opensuse.security:def:34593
    P
    Security update for postgresql, postgresql13, postgresql14 (Important)
    2021-11-20
    oval:org.opensuse.security:def:35277
    P
    Security update for the Linux Kernel (Important)
    2021-11-19
    oval:org.opensuse.security:def:33996
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:34581
    P
    Security update for opensc (Important)
    2021-10-29
    oval:org.opensuse.security:def:34582
    P
    Security update for transfig (Important)
    2021-10-29
    oval:org.opensuse.security:def:30259
    P
    Security update for postgresql10 (Important)
    2021-10-20
    oval:org.opensuse.security:def:31283
    P
    Security update for apache2 (Important)
    2021-10-06
    oval:org.opensuse.security:def:34514
    P
    Security update for qemu (Moderate)
    2021-08-23
    oval:org.opensuse.security:def:33960
    P
    Security update for cpio (Important)
    2021-08-23
    oval:org.opensuse.security:def:31234
    P
    Security update for the Linux Kernel (Live Patch 37 for SLE 12 SP3) (Important)
    2021-07-27
    oval:org.opensuse.security:def:30106
    P
    Security update for linuxptp (Important)
    2021-07-21
    oval:org.opensuse.security:def:34470
    P
    Security update for xterm (Important)
    2021-06-18
    oval:org.opensuse.security:def:33670
    P
    Security update for qemu (Important)
    2021-06-10
    oval:org.opensuse.security:def:33669
    P
    Security update for caribou (Important)
    2021-06-10
    oval:org.opensuse.security:def:33921
    P
    Security update for the Linux Kernel (Important)
    2021-06-08
    oval:org.opensuse.security:def:36115
    P
    ecryptfs-utils-32bit-61-1.33.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36074
    P
    OpenEXR-1.6.1-83.17.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:32915
    P
    Security update for libxml2 (Moderate)
    2021-05-05
    oval:org.opensuse.security:def:33900
    P
    Security update for java-1_7_0-openjdk (Moderate)
    2021-04-29
    oval:org.opensuse.security:def:34406
    P
    Security update for the Linux Kernel (Important)
    2021-04-13
    oval:org.opensuse.security:def:31140
    P
    Security update for the Linux Kernel (Live Patch 31 for SLE 12 SP3) (Important)
    2021-04-07
    oval:org.opensuse.security:def:32063
    P
    Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP3) (Important)
    2021-04-07
    oval:org.opensuse.security:def:31343
    P
    Security update for bind (Important)
    2021-02-18
    oval:org.opensuse.security:def:33764
    P
    Security update for openvswitch (Important)
    2021-02-15
    oval:org.opensuse.security:def:33071
    P
    Security update for python (Important)
    2021-02-11
    oval:org.opensuse.security:def:30020
    P
    Security update for python (Important)
    2021-02-11
    oval:org.opensuse.security:def:31322
    P
    Security update for the Linux Kernel (Live Patch 36 for SLE 12 SP3) (Important)
    2021-02-10
    oval:org.opensuse.security:def:33681
    P
    Security update for postgresql, postgresql12, postgresql13 (Important)
    2021-01-26
    oval:org.opensuse.security:def:34445
    P
    Security update for dovecot22 (Important)
    2021-01-04
    oval:org.opensuse.security:def:31178
    P
    Security update for flac (Moderate)
    2021-01-04
    oval:org.opensuse.security:def:29963
    P
    Security update for xen (Moderate)
    2020-12-22
    oval:org.opensuse.security:def:32828
    P
    Security update for python36 (Important)
    2020-12-11
    oval:org.opensuse.security:def:29744
    P
    Security update for gcc43 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35436
    P
    Security update for openvpn (Important)
    2020-12-01
    oval:org.opensuse.security:def:28454
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:31023
    P
    Security update for java-1_7_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:33216
    P
    openCryptoki on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28738
    P
    Security update for libQt
    2020-12-01
    oval:org.opensuse.security:def:35192
    P
    Security update for lha (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30314
    P
    Security update for tcpdump (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29031
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:31387
    P
    Security update for openvpn-openssl1 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32453
    P
    Security update for xfsprogs (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34969
    P
    Security update for gd
    2020-12-01
    oval:org.opensuse.security:def:30421
    P
    Security update for xorg-x11-libXrender
    2020-12-01
    oval:org.opensuse.security:def:30571
    P
    Security update for libxslt
    2020-12-01
    oval:org.opensuse.security:def:29173
    P
    Security update for microcode_ctl (Important)
    2020-12-01
    oval:org.opensuse.security:def:32677
    P
    gpg2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30657
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34299
    P
    Security update for python27 (Important)
    2020-12-01
    oval:org.opensuse.security:def:29872
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:29671
    P
    Security update for dhcpcd
    2020-12-01
    oval:org.opensuse.security:def:35392
    P
    Security update for opensc (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28443
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:30936
    P
    Security update for glib2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33177
    P
    librpcsecgss on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28653
    P
    Security update for dbus-1
    2020-12-01
    oval:org.opensuse.security:def:35152
    P
    Security update for kernel-source (Important)
    2020-12-01
    oval:org.opensuse.security:def:33283
    P
    w3m on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28879
    P
    security update for xen (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32452
    P
    Security update for xerces-j2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34912
    P
    Security update for e2fsprogs (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30402
    P
    Security update for Xen
    2020-12-01
    oval:org.opensuse.security:def:29134
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:32542
    P
    kvm on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35218
    P
    Security update for libksba
    2020-12-01
    oval:org.opensuse.security:def:31103
    P
    Security update for kernel-source (Important)
    2020-12-01
    oval:org.opensuse.security:def:30583
    P
    Security update for ntp (Important)
    2020-12-01
    oval:org.opensuse.security:def:34142
    P
    Security update for openldap2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29234
    P
    Security update for quagga (Important)
    2020-12-01
    oval:org.opensuse.security:def:29660
    P
    Security update for curl (Important)
    2020-12-01
    oval:org.opensuse.security:def:35365
    P
    Security update for ncurses (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28442
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:30879
    P
    Security update for fetchmail (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29876
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:33128
    P
    krb5 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28522
    P
    Security update for openvpn-openssl1 (Important)
    2020-12-01
    oval:org.opensuse.security:def:33239
    P
    puppet on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28795
    P
    Recommended update for openldap2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34813
    P
    Security update for php53
    2020-12-01
    oval:org.opensuse.security:def:30363
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29085
    P
    Security update for emacs (Important)
    2020-12-01
    oval:org.opensuse.security:def:32025
    P
    Security update for kernel-source (Important)
    2020-12-01
    oval:org.opensuse.security:def:32464
    P
    Security update for xorg-x11-libXrender (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35059
    P
    Security update for java-1_6_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:30465
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:30572
    P
    Security update for MozillaFirefox, mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:29190
    P
    Security update for ntp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29659
    P
    Security update for curl (Important)
    2020-12-01
    oval:org.opensuse.security:def:32771
    P
    perl-libwww-perl on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35326
    P
    Security update for microcode_ctl (Important)
    2020-12-01
    oval:org.opensuse.security:def:30789
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:34357
    P
    Security update for system-config-printer (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29908
    P
    Security update for lha (Moderate)
    2020-12-01
    oval:com.ubuntu.precise:def:20161925000
    V
    CVE-2016-1925 on Ubuntu 12.04 LTS (precise) - medium.
    2017-01-23
    BACK
    lha_for_unix_project lha for unix -