CVE-2015-0906: Lhaplus

Medium severity, CVSS 5.8. EPSS: 1.5% chance of exploitation in the next 30 days.

Directory traversal vulnerability in Lhaplus before 1.70 allows remote attackers to write to arbitrary files via a crafted archive.

Affected products

  • Lhaplus Lhaplus: up to and including 1.59; version 1.52 only; version 1.53 only; version 1.55 only; version 1.56 only; version 1.57 only

Published 2015-04-15. Last modified 2026-06-17.