|
|
Subscribe / Log in / New account

sharutils: arbitrary code execution

Package(s):sharutils CVE #(s):CAN-2004-1772
Created:October 1, 2004 Updated:April 26, 2005
Description: sharutils contains two buffer overflows. Ulf Harnhammar discovered a buffer overflow in shar.c, where the length of data returned by the wc command is not checked. Florian Schilhabel discovered another buffer overflow in unshar.c. An attacker could exploit these vulnerabilities to execute arbitrary code as the user running one of the sharutils programs.
Alerts:
Red Hat RHSA-2005:377-01 sharutils 2005-04-26
Fedora FEDORA-2005-281 sharutils 2005-04-01
Fedora FEDORA-2005-280 sharutils 2005-04-01
Ubuntu USN-102-1 sharutils 2005-03-29
Fedora-Legacy FLSA:2155 sharutils 2005-03-24
Gentoo 200410-01 sharutils 2004-10-01

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds