CVE-2005-2856
Stack-based buffer overflow in the WinACE UNACEV2.DLL third-party compression utility before 2.6.0.0, as used in multiple products including (1) ALZip 5.51 through 6.11, (2) Servant Salamander 2.0 and 2.5 Beta 1, (3) WinHKI 1.66 and 1.67, (4) ExtractNow…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 15.7%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Stack-based buffer overflow in the WinACE UNACEV2.DLL third-party compression utility before 2.6.0.0, as used in multiple products including (1) ALZip 5.51 through 6.11, (2) Servant Salamander 2.0 and 2.5 Beta 1, (3) WinHKI 1.66 and 1.67, (4) ExtractNow 3.x, (5) Total Commander 6.53, (6) Anti-Trojan 5.5.421, (7) PowerArchiver before 9.61, (8) UltimateZip 2.7,1, 3.0.3, and 3.1b, (9) Where Is It (WhereIsIt) 3.73.501, (10) FilZip 3.04, (11) IZArc 3.5 beta3, (12) Eazel 1.0, (13) Rising Antivirus 18.27.21 and earlier, (14) AutoMate 6.1.0.0, (15) BitZipper 4.1 SR-1, (16) ZipTV, and other products, allows user-assisted attackers to execute arbitrary code via a long filename in an ACE archive.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 15.68% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- winace/winace
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=112621008228458&w=2
- http://secunia.com/advisories/16479Patch, Vendor Advisory
- http://secunia.com/advisories/19454Vendor Advisory
- http://secunia.com/advisories/19458Vendor Advisory
- http://secunia.com/advisories/19581Vendor Advisory
- http://secunia.com/advisories/19596
- http://secunia.com/advisories/19612
- http://secunia.com/advisories/19834Vendor Advisory
- http://secunia.com/advisories/19890Vendor Advisory
- http://secunia.com/advisories/19931
- http://secunia.com/advisories/19938Vendor Advisory
- http://secunia.com/advisories/19939
- http://secunia.com/advisories/19967Vendor Advisory
- http://secunia.com/advisories/19975Vendor Advisory
- http://secunia.com/advisories/19977Vendor Advisory
- http://secunia.com/advisories/20009Vendor Advisory
- http://secunia.com/advisories/20270
- http://secunia.com/secunia_research/2005-41/advisory/
- http://secunia.com/secunia_research/2006-24/advisoryVendor Advisory
- http://secunia.com/secunia_research/2006-25/advisoryVendor Advisory
- http://secunia.com/secunia_research/2006-27/Vendor Advisory
- http://secunia.com/secunia_research/2006-28/advisoryVendor Advisory
- http://secunia.com/secunia_research/2006-29/advisory/Vendor Advisory
- http://secunia.com/secunia_research/2006-30/advisoryVendor Advisory
- http://secunia.com/secunia_research/2006-32/advisory/
- http://secunia.com/secunia_research/2006-33/advisory/Vendor Advisory
- http://secunia.com/secunia_research/2006-36/advisoryVendor Advisory
- http://secunia.com/secunia_research/2006-38/advisoryVendor Advisory
- http://secunia.com/secunia_research/2006-46/advisory/
- http://secunia.com/secunia_research/2006-50/advisory/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.