Vulnerability Name: | CVE-2004-0947 (CCN-18044) | ||||||||||||
Assigned: | 2004-11-11 | ||||||||||||
Published: | 2004-11-11 | ||||||||||||
Updated: | 2017-07-11 | ||||||||||||
Summary: | Buffer overflow in unarj before 2.63a-r2 allows remote attackers to execute arbitrary code via an arj archive that contains long filenames. | ||||||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2004-0947 Source: FEDORA Type: UNKNOWN FLSA:2272 Source: CCN Type: RHSA-2005-007 unarj security update Source: CCN Type: ARJ Software Web site ARJ Software Source: DEBIAN Type: UNKNOWN DSA-652 Source: DEBIAN Type: DSA-652 unarj -- several vulnerabilities Source: CCN Type: GLSA-200411-29 unarj: Long filenames buffer overflow and a path traversal vulnerability Source: GENTOO Type: Patch, Vendor Advisory GLSA-200411-29 Source: REDHAT Type: UNKNOWN RHSA-2005:007 Source: BID Type: Patch, Vendor Advisory 11665 Source: CCN Type: BID-11665 ARJ Software UNARJ Remote Buffer Overflow Vulnerability Source: XF Type: UNKNOWN unarj-longfilename-bo(18044) Source: XF Type: UNKNOWN unarj-longfilename-bo(18044) Source: SUSE Type: SUSE-SR:2004:003 SUSE Security Summary Report | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: ![]() | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |