CVE-2005-4667
Buffer overflow in UnZip 5.50 and earlier allows user-assisted attackers to execute arbitrary code via a long filename command line argument. NOTE: since the overflow occurs in a non-setuid program, there are not many scenarios under which it poses a vulnerability, unless unzip is passed long arguments when it is invoked from other programs.
- Info-zip Unzip
- = 5.2, 5.3, 5.31, 5.32, 5.40, 5.41, 5.42, 5.50
- Fix
- Available
- CVSS 2.0
- 3.7 LOW
- EPSS
- 1.5% (73th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2006-01-25
CVE-2005-4667 at NVD
1 known exploit for CVE-2005-4667
Proof-of-concept code and exploit modules indexed by Sploitus