Buffer overflow in Arcext.dll 2.16.1 and earlier in pon software Explzh 5.62 and earlier allows remote attackers to execute arbitrary code via an LZH LHA file with a crafted header that is not properly handled during expansion.Referenceshttp://osvdb.org/65666http://www.securityfocus.com/bid/41025http://www.ponsoftware.com/archiver/bug.htm#lzh_bufoverhttp://secunia.com/advisories/40324http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000026.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/59624http://jvn.jp/en/jp/JVN34729123/index.html