cve/2008/CVE-2008-4420.md
2024-06-18 02:51:15 +02:00

19 lines
953 B
Markdown

### [CVE-2008-4420](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4420)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
Multiple stack-based buffer overflows in DZIP32.DLL before 5.0.0.8 in DynaZip Max and DZIPS32.DLL before 6.0.0.5 in DynaZip Max Secure; as used in HP OpenView Performance Agent C.04.60, HP Performance Agent C.04.70 and C.04.72, TurboZIP 6.0, and other products; allow user-assisted attackers to execute arbitrary code via a long filename in a ZIP archive during a (1) Fix (aka Repair), (2) Add, (3) Update, or (4) Freshen action, a related issue to CVE-2006-3985.
### POC
#### Reference
- http://vuln.sg/dynazip5007-en.html
- http://vuln.sg/turbozip6-en.html
#### Github
No PoCs found on GitHub currently.