7.5 High
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
7.9 High
AI Score
Confidence
High
0.041 Low
EPSS
Percentile
92.2%
Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code via ZIP files containing entries with long filenames, including (1) Microsoft Windows 98 with Plus! Pack, (2) Windows XP, (3) Windows ME, (4) Lotus Notes R4 through R6 (pre-gold), (5) Verity KeyView, and (6) Stuffit Expander before 7.0.
archives.neohapsis.com/archives/vulnwatch/2002-q4/0009.html
marc.info/?l=bugtraq&m=103428193409223&w=2
securityreason.com/securityalert/587
www.info-zip.org/FAQ.html
www.info.apple.com/usen/security/security_updates.html
www.iss.net/security_center/static/10251.php
www.kb.cert.org/vuls/id/383779
www.securityfocus.com/bid/5873
docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-054