VYPR

Sharutils

by GNU

CVEs (4)

  • CVE-2005-0990May 2, 2005
    risk 0.00cvss epss 0.00

    unshar (unshar.c) in sharutils 4.2.1 allows local users to overwrite arbitrary files via a symlink attack on the unsh.X temporary file.

  • CVE-2004-1773Dec 31, 2004
    risk 0.00cvss epss 0.02

    Multiple buffer overflows in sharutils 4.2.1 and earlier may allow attackers to execute arbitrary code via (1) long output from wc to shar, or (2) unknown vectors in unshar.

  • CVE-2004-1772Dec 31, 2004
    risk 0.00cvss epss 0.00

    Stack-based buffer overflow in shar in GNU sharutils 4.2.1 allows local users to execute arbitrary code via a long -o command line argument.

  • CVE-2002-0178May 29, 2002
    risk 0.00cvss epss 0.00

    uudecode, as available in the sharutils package before 4.2.1, does not check whether the filename of the uudecoded file is a pipe or symbolic link, which could allow attackers to overwrite files or execute commands.