9.3
CVSSv2

CVE-2007-1614

Published: 23/03/2007 Updated: 08/03/2011
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Stack-based buffer overflow in the zzip_open_shared_io function in zzip/file.c in ZZIPlib Library prior to 0.13.49 allows user-assisted remote malicious users to cause a denial of service (application crash) or execute arbitrary code via a long filename.

Vulnerable Product Search on Vulmon Subscribe to Product

zziplib zziplib

Vendor Advisories

Debian Bug report logs - #436701 CVE-2007-1614: DoS and execution of arbitary code Package: zziplib; Maintainer for zziplib is Scott Howard <showard@debianorg>; Reported by: Steffen Joeris <steffenjoeris@skolelinuxde> Date: Wed, 8 Aug 2007 15:09:01 UTC Severity: normal Tags: security Fixed in version zziplib/01 ...