CVE-2016-1925
9.8
CRITICAL · CVSS 3.0 · EPSS 3% (pctl 87)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Integer underflow in header.c in lha allows remote attackers to have unspecified impact via a large header size value for the (1) level0 or (2) level1 header in a lha archive, which triggers a buffer overflow.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 2.99% — more likely to be exploited than 87% of all CVEs |
| Weakness | CWE-191 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2017-01-23 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| lha for unix project | lha for unix |
References
- http://www.openwall.com/lists/oss-security/2016/01/18/3
- http://www.openwall.com/lists/oss-security/2016/01/18/8
- https://security.gentoo.org/glsa/202007-42
- http://www.openwall.com/lists/oss-security/2016/01/18/3
- http://www.openwall.com/lists/oss-security/2016/01/18/8
- https://security.gentoo.org/glsa/202007-42
→ the Explorer · watch your stack · NVD