Unrated severityNVD Advisory· Published Aug 14, 2006· Updated Apr 16, 2026
CVE-2006-4116
CVE-2006-4116
Description
Multiple stack-based buffer overflows in Lhaz before 1.32 allow user-assisted attackers to execute arbitrary code via a long filename in (1) an LHZ archive, when saving the filename during extraction; and (2) an LHZ archive with an invalid CRC checksum, when constructing an error message.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- secunia.com/advisories/21348nvdExploitPatchVendor Advisory
- vuln.sg/lhaz131-en.htmlnvdExploitPatch
- securityreason.com/securityalert/1378nvd
- www.chitora.jp/lhaz.htmlnvd
- www.securityfocus.com/archive/1/442445/100/0/threadednvd
- www.securityfocus.com/bid/19377nvd
- www.vupen.com/english/advisories/2006/3173nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/28282nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/28283nvd
News mentions
0No linked articles in our index yet.