VulnerabilityModified
CVE-2006-2161
Buffer overflow in (1) TZipBuilder 1.79.03.01, (2) Abakt 0.9.2 and 0.9.3-beta1, (3) CAM UnZip 4.0 and 4.3, and possibly other products, allows user-assisted attackers to execute arbitrary code via a ZIP archive that contains a file with a long file name.
MEDIUM 5.1EPSS 3.60%
Does this matter?
Lower severity and a low EPSS score (3.60%). Track it; it rarely justifies an emergency change on its own.
Description
Buffer overflow in (1) TZipBuilder 1.79.03.01, (2) Abakt 0.9.2 and 0.9.3-beta1, (3) CAM UnZip 4.0 and 4.3, and possibly other products, allows user-assisted attackers to execute arbitrary code via a ZIP archive that contains a file with a long file name.
- CVSS 2.0
- 5.1 MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
- EPSS
- 3.60% probability · 89th percentile
- CISA KEV
- Not listed
- Affected
- cam development/cam unzip · erik dienske/abakt · roger aelbrecht/tzipbuilder
- Source
- PSIRT-CNA@flexerasoftware.com
References
- http://marc.info/?l=full-disclosure&m=114771024009857&w=2
- http://secunia.com/advisories/19945Patch, Vendor Advisory
- http://secunia.com/advisories/19946Patch, Vendor Advisory
- http://secunia.com/advisories/20068Patch, Vendor Advisory
- http://secunia.com/secunia_research/2006-26/advisoryVendor Advisory
- http://secunia.com/secunia_research/2006-31/advisory/Patch, Vendor Advisory
- http://secunia.com/secunia_research/2006-34/advisory/Patch, Vendor Advisory
- http://securityreason.com/securityalert/853
- http://securitytracker.com/id?1016064Patch
- http://securitytracker.com/id?1016107Patch
- http://www.securityfocus.com/archive/1/433257/100/0/threaded
- http://www.securityfocus.com/archive/1/434019/100/0/threaded
- http://www.securityfocus.com/archive/1/434520/100/0/threaded
- http://www.securityfocus.com/bid/17880Patch
- http://www.vupen.com/english/advisories/2006/1687
- http://www.vupen.com/english/advisories/2006/1805
- http://www.vupen.com/english/advisories/2006/1865
- http://www.xs4all.nl/~edienske/abakt/releases.html#0.9.3-RC1
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26275
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26435
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26549
- http://marc.info/?l=full-disclosure&m=114771024009857&w=2
- http://secunia.com/advisories/19945Patch, Vendor Advisory
- http://secunia.com/advisories/19946Patch, Vendor Advisory
- http://secunia.com/advisories/20068Patch, Vendor Advisory
- http://secunia.com/secunia_research/2006-26/advisoryVendor Advisory
- http://secunia.com/secunia_research/2006-31/advisory/Patch, Vendor Advisory
- http://secunia.com/secunia_research/2006-34/advisory/Patch, Vendor Advisory
- http://securityreason.com/securityalert/853
- http://securitytracker.com/id?1016064Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.