PT-2005-5332 · Info Zip+1 · Unzip+1
C0Ntex
·
Publicado
2005-12-31
·
Atualizado
2018-10-19
·
CVE-2005-4667
CVSS v2.0
3.7
Baixa
| Vetor | AV:L/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
UnZip versions 5.50 and earlier
Description
The issue allows user-assisted attackers to execute arbitrary code via a long filename command line argument. However, since the overflow occurs in a non-setuid program, the risk is relatively low unless UnZip is passed long arguments when invoked from other programs.
Recommendations
For UnZip versions 5.50 and earlier, consider avoiding the use of long filename command line arguments until a fix is available. As a temporary workaround, restrict the length of filename arguments passed to UnZip to prevent potential exploitation.
Exploit
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Red Hat
Unzip