Lucene search

K
cve[email protected]CVE-2008-4420
HistoryApr 13, 2009 - 4:30 p.m.

CVE-2008-4420

2009-04-1316:30:00
CWE-119
web.nvd.nist.gov
22
cve-2008-4420
buffer overflow
dzip32.dll
dzips32.dll
dynazip max
hp openview
turbozip

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.8 High

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

75.7%

Multiple stack-based buffer overflows in DZIP32.DLL before 5.0.0.8 in DynaZip Max and DZIPS32.DLL before 6.0.0.5 in DynaZip Max Secure; as used in HP OpenView Performance Agent C.04.60, HP Performance Agent C.04.70 and C.04.72, TurboZIP 6.0, and other products; allow user-assisted attackers to execute arbitrary code via a long filename in a ZIP archive during a (1) Fix (aka Repair), (2) Add, (3) Update, or (4) Freshen action, a related issue to CVE-2006-3985.

Affected configurations

NVD
Node
microsoftwindows
AND
hpopenview_performance_agentMatchc.04.60
OR
hpopenview_performance_agentMatchc.04.70
OR
hpopenview_performance_agentMatchc.04.72
Node
innermediadynazip_maxRange5.0.0.7
OR
innermediadynazip_max_secureRange6.0.0.4
Node
filestreamturbozipMatch6.0

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.8 High

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

75.7%