CVE-2016-1925: Lha For Unix Project Lha For Unix
Critical severity, CVSS 9.8. EPSS: 3% chance of exploitation in the next 30 days.
Integer underflow in header.c in lha allows remote attackers to have unspecified impact via a large header size value for the (1) level0 or (2) level1 header in a lha archive, which triggers a buffer overflow.
Affected products
- Lha For Unix Project Lha For Unix: affected versions not specified
Published 2017-01-23. Last modified 2026-06-17.