CVE-2008-4420
Multiple stack-based buffer overflows in DZIP32.DLL before 5.0.0.8 in DynaZip Max and DZIPS32.DLL before 6.0.0.5 in DynaZip Max Secure; as used in HP OpenView Performance Agent C.04.60, HP Performance Agent C.04.70 and C.04.72, TurboZIP 6.0, and other…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.66%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple stack-based buffer overflows in DZIP32.DLL before 5.0.0.8 in DynaZip Max and DZIPS32.DLL before 6.0.0.5 in DynaZip Max Secure; as used in HP OpenView Performance Agent C.04.60, HP Performance Agent C.04.70 and C.04.72, TurboZIP 6.0, and other products; allow user-assisted attackers to execute arbitrary code via a long filename in a ZIP archive during a (1) Fix (aka Repair), (2) Add, (3) Update, or (4) Freshen action, a related issue to CVE-2006-3985.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 5.66% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- hp/openview performance agent · innermedia/dynazip max · innermedia/dynazip max secure · filestream/turbozip
- Source
- cve@mitre.org
References
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01622011Vendor Advisory
- http://innermedia.com/upgrades.html
- http://osvdb.org/53478
- http://secunia.com/advisories/21180Vendor Advisory
- http://secunia.com/advisories/34659Vendor Advisory
- http://vuln.sg/dynazip5007-en.htmlExploit
- http://vuln.sg/turbozip6-en.html
- http://www.securityfocus.com/archive/1/441083
- http://www.securityfocus.com/archive/1/441084
- http://www.securityfocus.com/bid/19143Patch
- http://www.securitytracker.com/id?1022021
- http://www.vupen.com/english/advisories/2006/2957Vendor Advisory
- http://www.vupen.com/english/advisories/2009/0980Vendor Advisory
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01622011Vendor Advisory
- http://innermedia.com/upgrades.html
- http://osvdb.org/53478
- http://secunia.com/advisories/21180Vendor Advisory
- http://secunia.com/advisories/34659Vendor Advisory
- http://vuln.sg/dynazip5007-en.htmlExploit
- http://vuln.sg/turbozip6-en.html
- http://www.securityfocus.com/archive/1/441083
- http://www.securityfocus.com/archive/1/441084
- http://www.securityfocus.com/bid/19143Patch
- http://www.securitytracker.com/id?1022021
- http://www.vupen.com/english/advisories/2006/2957Vendor Advisory
- http://www.vupen.com/english/advisories/2009/0980Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.