Lucene search

K
jvnJapan Vulnerability NotesJVN:62868899
HistorySep 05, 2007 - 12:00 a.m.

JVN#62868899 7-ZIP32.DLL buffer overflow vulnerability

2007-09-0500:00:00
Japan Vulnerability Notes
jvn.jp
27

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.107

Percentile

95.1%

7-ZIP32.DLL is an open source library for compression and decompression supporting 7z, zip, and some other format files. 7-ZIP32.DLL is based on “Integrated Archiver API Specification”, and called from the compression/decompression software. 7-ZIP32.DLL contains a buffer overflow vulnerability. If a user decompresses and opens a specially crafted file, a remote attacker could possibly execute arbitrary code with the privilege of the user.

Impact

Arbitrary code could be executed with the privilege of a user who opened a specially crafted file.

Solution

Upgrade
Apply the latest updates provided by the developer.

For more information, refer to the developer’s website.

Products Affected

7-ZIP32.DLL Version 4.42.00.03 and earlier

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.107

Percentile

95.1%

Related for JVN:62868899