CVE-2005-3831
Published Nov 26, 2005
Last updated 6 years ago
Overview
- Description
- Stack-based buffer overflow in (1) CxZIP60.dll and (2) CxZIP60u.dll, as used in SpeedProject products including (a) ZipStar 5.0 Build 4285, (b) Squeez 5.0 Build 4285, and (c) SpeedCommander 11.0 Build 4430 and 10.51 Build 4430, allows user-assisted attackers to execute arbitrary code via a ZIP archive containing a long filename.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5.1
- Impact score
- 6.4
- Exploitability score
- 4.9
- Vector string
- AV:N/AC:H/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-119
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:speedproject:speedcommander:10.51_build4430:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B3DDD6C4-9A56-479D-8E0B-2FE579C64387" }, { "criteria": "cpe:2.3:a:speedproject:speedcommander:11.0_build4430:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "53E30983-D8AC-46AE-B779-BCDBC40DF5BC" }, { "criteria": "cpe:2.3:a:speedproject:squeez:5.0_build_4285:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8E8A7318-F5C2-4A74-83B5-80BDEFCDF1C3" }, { "criteria": "cpe:2.3:a:speedproject:zipstar:5.0_build_4285:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BDC48414-ECB2-42E2-9EBE-F88FA8D1C846" } ], "operator": "OR" } ] } ]