lharc.c in lha does not securely create temporary files, which might allow local users to read or write files by creating a file before LHA is invoked.
| Software | From | Fixed in |
|---|---|---|
| redhat / enterprise_linux | 4.0 | 4.0.x |
| redhat / enterprise_linux | 2.1 | 2.1.x |
| redhat / fedora_core | core_5.0 | core_5.0.x |
| redhat / enterprise_linux | 3.0 | 3.0.x |