Lucene search

K
cveMitreCVE-2005-3051
HistorySep 24, 2005 - 12:03 a.m.

CVE-2005-3051

2005-09-2400:03:00
CWE-119
mitre
web.nvd.nist.gov
33
cve-2005-3051
arj plugin
7-zip
buffer overflow
remote code execution

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8

Confidence

Low

EPSS

0.146

Percentile

95.9%

Stack-based buffer overflow in the ARJ plugin (arj.dll) 3.9.2.0 for 7-Zip 3.13, 4.23, and 4.26 BETA, as used in products including Turbo Searcher, allows remote attackers to execute arbitrary code via a large ARJ block.

Affected configurations

Nvd
Node
igor_pavlov7-zipMatch3.13
OR
igor_pavlov7-zipMatch4.23
OR
igor_pavlov7-zipMatch4.26_beta
VendorProductVersionCPE
igor_pavlov7-zip3.13cpe:2.3:a:igor_pavlov:7-zip:3.13:*:*:*:*:*:*:*
igor_pavlov7-zip4.23cpe:2.3:a:igor_pavlov:7-zip:4.23:*:*:*:*:*:*:*
igor_pavlov7-zip4.26_betacpe:2.3:a:igor_pavlov:7-zip:4.26_beta:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8

Confidence

Low

EPSS

0.146

Percentile

95.9%