PT-2002-1433 · Ibm+3 · Lotus Notes+5

Published

2002-10-05

·

Updated

2018-10-12

·

CVE-2002-0370

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Windows 98 with Plus! Pack Windows XP Windows ME Lotus Notes versions R4 through R6 (pre-gold) Verity KeyView (affected versions not specified) Stuffit Expander versions prior to 7.0
Description A buffer overflow issue exists in the ZIP capability of multiple products, allowing remote attackers to cause a denial of service or execute arbitrary code via ZIP files containing entries with long filenames.
Recommendations For Microsoft Windows 98 with Plus! Pack, update to a version that includes the fix for this issue. For Windows XP, apply the necessary patch to resolve the buffer overflow issue. For Windows ME, ensure all security updates are applied to mitigate the risk. For Lotus Notes versions R4 through R6 (pre-gold), consider upgrading to a version outside the affected range. For Verity KeyView, at the moment, there is no information about a newer version that contains a fix for this issue. For Stuffit Expander versions prior to 7.0, update to version 7.0 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0370

Affected Products

Lotus Notes
Stuffit Expander
Verity Keyview
Windows 98
Windows Me
Windows Xp