Gentoo Linux Security Advisory GLSA 200611-24 – Tavis Ormandy of the Google Security Team discovered several vulnerabilities in the LZH decompression component used by LHa. The make_table function of unlzh.c contains an array index error and a buffer overflow vulnerability. The build_tree function of unpack.c contains a buffer underflow vulnerability. Additionally, unlzh.c contains a code that could run in an infinite loop. Versions less than 114i-r6 are affected.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/52619/glsa-200611-24.txt
Source: https://packetstormsecurity.com/files/52619/Gentoo-Linux-Security-Advisory-200611-24.html

