Description
LHA 1.14 and earlier allows attackers to execute arbitrary commands via a directory with shell metacharacters in its name.
Affected products
References
- MISChttp://www.redhat.com/support/errata/RHSA-2004-323.html
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11088
- MISChttps://bugzilla.fedora.us/show_bug.cgi?id=1833
- MISChttp://www.gentoo.org/security/en/glsa/glsa-200409-13.xml
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/17198
- MISChttp://www.redhat.com/support/errata/RHSA-2004-440.html