Vulnerability Description
Stack-based buffer overflow in the WinACE UNACEV2.DLL third-party compression utility before 2.6.0.0, as used in multiple products including (1) ALZip 5.51 through 6.11, (2) Servant Salamander 2.0 and 2.5 Beta 1, (3) WinHKI 1.66 and 1.67, (4) ExtractNow 3.x, (5) Total Commander 6.53, (6) Anti-Trojan 5.5.421, (7) PowerArchiver before 9.61, (8) UltimateZip 2.7,1, 3.0.3, and 3.1b, (9) Where Is It (WhereIsIt) 3.73.501, (10) FilZip 3.04, (11) IZArc 3.5 beta3, (12) Eazel 1.0, (13) Rising Antivirus 18.27.21 and earlier, (14) AutoMate 6.1.0.0, (15) BitZipper 4.1 SR-1, (16) ZipTV, and other products, allows user-assisted attackers to execute arbitrary code via a long filename in an ACE archive.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Winace | Winace | 2.6.0.0 |
Related Weaknesses (CWE)
References
- http://marc.info/?l=bugtraq&m=112621008228458&w=2
- http://secunia.com/advisories/16479PatchVendor Advisory
- http://secunia.com/advisories/19454Vendor Advisory
- http://secunia.com/advisories/19458Vendor Advisory
- http://secunia.com/advisories/19581Vendor Advisory
- http://secunia.com/advisories/19596
- http://secunia.com/advisories/19612
- http://secunia.com/advisories/19834Vendor Advisory
- http://secunia.com/advisories/19890Vendor Advisory
- http://secunia.com/advisories/19931
- http://secunia.com/advisories/19938Vendor Advisory
- http://secunia.com/advisories/19939
- http://secunia.com/advisories/19967Vendor Advisory
- http://secunia.com/advisories/19975Vendor Advisory
- http://secunia.com/advisories/19977Vendor Advisory
FAQ
What is CVE-2005-2856?
CVE-2005-2856 is a vulnerability with a CVSS score of 7.5 (HIGH). Stack-based buffer overflow in the WinACE UNACEV2.DLL third-party compression utility before 2.6.0.0, as used in multiple products including (1) ALZip 5.51 through 6.11, (2) Servant Salamander 2.0 and...
How severe is CVE-2005-2856?
CVE-2005-2856 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-2856?
Check the references section above for vendor advisories and patch information. Affected products include: Winace Winace.