PT-2005-5332 · Info Zip+1 · Unzip+1

C0Ntex

·

Publicado

2005-12-31

·

Atualizado

2018-10-19

·

CVE-2005-4667

CVSS v2.0

3.7

Baixa

VetorAV:L/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions UnZip versions 5.50 and earlier
Description The issue allows user-assisted attackers to execute arbitrary code via a long filename command line argument. However, since the overflow occurs in a non-setuid program, the risk is relatively low unless UnZip is passed long arguments when invoked from other programs.
Recommendations For UnZip versions 5.50 and earlier, consider avoiding the use of long filename command line arguments until a fix is available. As a temporary workaround, restrict the length of filename arguments passed to UnZip to prevent potential exploitation.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2005-4667
DSA-1012-1
RHSA-2007:0203
RHSA-2007_0203

Produtos afetados

Red Hat
Unzip