Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2005-4667

Опубликовано: 31 дек. 2005
Источник: nvd
CVSS2: 3.7
EPSS Низкий

Описание

Buffer overflow in UnZip 5.50 and earlier allows user-assisted attackers to execute arbitrary code via a long filename command line argument. NOTE: since the overflow occurs in a non-setuid program, there are not many scenarios under which it poses a vulnerability, unless unzip is passed long arguments when it is invoked from other programs.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:info-zip:unzip:5.2:*:*:*:*:*:*:*
cpe:2.3:a:info-zip:unzip:5.3:*:*:*:*:*:*:*
cpe:2.3:a:info-zip:unzip:5.31:*:*:*:*:*:*:*
cpe:2.3:a:info-zip:unzip:5.32:*:*:*:*:*:*:*
cpe:2.3:a:info-zip:unzip:5.40:*:*:*:*:*:*:*
cpe:2.3:a:info-zip:unzip:5.41:*:*:*:*:*:*:*
cpe:2.3:a:info-zip:unzip:5.42:*:*:*:*:*:*:*
cpe:2.3:a:info-zip:unzip:5.50:*:*:*:*:*:*:*

EPSS

Процентиль: 86%
0.03134
Низкий

3.7 Low

CVSS2

Дефекты

CWE-119

Связанные уязвимости

ubuntu
больше 19 лет назад

Buffer overflow in UnZip 5.50 and earlier allows user-assisted attackers to execute arbitrary code via a long filename command line argument. NOTE: since the overflow occurs in a non-setuid program, there are not many scenarios under which it poses a vulnerability, unless unzip is passed long arguments when it is invoked from other programs.

redhat
больше 19 лет назад

Buffer overflow in UnZip 5.50 and earlier allows user-assisted attackers to execute arbitrary code via a long filename command line argument. NOTE: since the overflow occurs in a non-setuid program, there are not many scenarios under which it poses a vulnerability, unless unzip is passed long arguments when it is invoked from other programs.

debian
больше 19 лет назад

Buffer overflow in UnZip 5.50 and earlier allows user-assisted attacke ...

github
больше 3 лет назад

Buffer overflow in UnZip 5.50 and earlier allows user-assisted attackers to execute arbitrary code via a long filename command line argument. NOTE: since the overflow occurs in a non-setuid program, there are not many scenarios under which it poses a vulnerability, unless unzip is passed long arguments when it is invoked from other programs.

EPSS

Процентиль: 86%
0.03134
Низкий

3.7 Low

CVSS2

Дефекты

CWE-119