HIGH · 7.5

CVE-2002-0370

Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code via ZIP files containing entries with long filenames, includi...

Vulnerability Description

Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code via ZIP files containing entries with long filenames, including (1) Microsoft Windows 98 with Plus! Pack, (2) Windows XP, (3) Windows ME, (4) Lotus Notes R4 through R6 (pre-gold), (5) Verity KeyView, and (6) Stuffit Expander before 7.0.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
Allume Systems DivisionStuffit Expander6.5.2
IbmLotus Notes<= 4.5
VerityKeyview Viewing Sdkgold
WinzipWinzip7.0
MicrosoftWindows 98 Plus PackAll versions
MicrosoftWindows MeAll versions
MicrosoftWindows XpAll versions

References

FAQ

What is CVE-2002-0370?

CVE-2002-0370 is a vulnerability with a CVSS score of 7.5 (HIGH). Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code via ZIP files containing entries with long filenames, includi...

How severe is CVE-2002-0370?

CVE-2002-0370 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2002-0370?

Check the references section above for vendor advisories and patch information. Affected products include: Allume Systems Division Stuffit Expander, Ibm Lotus Notes, Verity Keyview Viewing Sdk, Winzip Winzip, Microsoft Windows 98 Plus Pack.