Lucene search

K
nvd[email protected]NVD:CVE-2008-4420
HistoryApr 13, 2009 - 4:30 p.m.

CVE-2008-4420

2009-04-1316:30:00
CWE-119
web.nvd.nist.gov

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.6 High

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

75.7%

Multiple stack-based buffer overflows in DZIP32.DLL before 5.0.0.8 in DynaZip Max and DZIPS32.DLL before 6.0.0.5 in DynaZip Max Secure; as used in HP OpenView Performance Agent C.04.60, HP Performance Agent C.04.70 and C.04.72, TurboZIP 6.0, and other products; allow user-assisted attackers to execute arbitrary code via a long filename in a ZIP archive during a (1) Fix (aka Repair), (2) Add, (3) Update, or (4) Freshen action, a related issue to CVE-2006-3985.

Affected configurations

NVD
Node
microsoftwindows
AND
hpopenview_performance_agentMatchc.04.60
OR
hpopenview_performance_agentMatchc.04.70
OR
hpopenview_performance_agentMatchc.04.72
Node
innermediadynazip_maxRange5.0.0.7
OR
innermediadynazip_max_secureRange6.0.0.4
Node
filestreamturbozipMatch6.0

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.6 High

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

75.7%

Related for NVD:CVE-2008-4420