Multiple buffer overflows in sharutils 4.2.1 and earlier may allow attackers to execute arbitrary code via (1) long output from wc to shar, or (2) unknown vectors in unshar.
| Software | From | Fixed in |
|---|---|---|
| gnu / sharutils | 4.2 | 4.2.x |
| gnu / sharutils | 4.2.1 | 4.2.1.x |