PT-2005-1258 · Unace · Unace

Ulf Harnhammar

·

Publicado

2005-02-22

·

Atualizado

2008-09-05

·

CVE-2005-0160

CVSS v2.0

5.1

Média

VetorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions unace version 1.2b
Description The issue is related to multiple buffer overflows that allow attackers to execute arbitrary code. This can be achieved through various means, including overflows in ACE archives, a long command line argument, or certain "Ready for next volume" messages.
Recommendations For unace version 1.2b, consider updating to a newer version that addresses these buffer overflows to prevent the execution of arbitrary code. As a temporary workaround, restrict the use of unace to minimize the risk of exploitation, especially when handling ACE archives or command line arguments from untrusted sources.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-0160

Produtos afetados

Unace