mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-05-28 09:11:28 +00:00
186 lines
5.7 KiB
JSON
186 lines
5.7 KiB
JSON
{
|
|
"id": "CVE-2007-4725",
|
|
"sourceIdentifier": "cve@mitre.org",
|
|
"published": "2007-09-05T19:17:00.000",
|
|
"lastModified": "2020-09-17T13:38:09.700",
|
|
"vulnStatus": "Analyzed",
|
|
"cveTags": [],
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "Stack consumption vulnerability in AkkyWareHOUSE 7-zip32.dll before 4.42.00.04, as derived from Igor Pavlov 7-Zip before 4.53 beta, allows user-assisted remote attackers to execute arbitrary code via a long filename in an archive, leading to a heap-based buffer overflow."
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": "Vulnerabilidad de consumo de pila en AkkyWareHOUSE 7-zip32.dll anterior a 4.42.00.04, como el derivado de Igor Pavlov 7-Zip anterior a 4.53 beta, permite a atacantes remotos con la complicidad del usuario ejecutar c\u00f3digo de su elecci\u00f3n mediante un nombre de fichero largo en un archivo, que acaba en un desbordamiento de b\u00fafer basado en pila."
|
|
}
|
|
],
|
|
"metrics": {
|
|
"cvssMetricV2": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"cvssData": {
|
|
"version": "2.0",
|
|
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
|
|
"accessVector": "NETWORK",
|
|
"accessComplexity": "MEDIUM",
|
|
"authentication": "NONE",
|
|
"confidentialityImpact": "PARTIAL",
|
|
"integrityImpact": "PARTIAL",
|
|
"availabilityImpact": "PARTIAL",
|
|
"baseScore": 6.8
|
|
},
|
|
"baseSeverity": "MEDIUM",
|
|
"exploitabilityScore": 8.6,
|
|
"impactScore": 6.4,
|
|
"acInsufInfo": false,
|
|
"obtainAllPrivilege": false,
|
|
"obtainUserPrivilege": false,
|
|
"obtainOtherPrivilege": false,
|
|
"userInteractionRequired": true
|
|
}
|
|
]
|
|
},
|
|
"weaknesses": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"description": [
|
|
{
|
|
"lang": "en",
|
|
"value": "CWE-400"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"configurations": [
|
|
{
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:7-zip:7-zip:*:*:*:*:*:*:*:*",
|
|
"versionEndIncluding": "4.42",
|
|
"matchCriteriaId": "E4781BF9-2A59-412C-BF69-E707EDD06383"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:7-zip:7-zip:4.43:beta:*:*:*:*:*:*",
|
|
"matchCriteriaId": "3071CC75-581A-4A34-A354-4ECA2C2ADD55"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:7-zip:7-zip:4.44:beta:*:*:*:*:*:*",
|
|
"matchCriteriaId": "AF85486D-6F16-4BD7-A318-8E80EF3E1E93"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:7-zip:7-zip:4.45:beta:*:*:*:*:*:*",
|
|
"matchCriteriaId": "ED9B7457-2349-4FF5-BE09-AB5E4E618B96"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:7-zip:7-zip:4.46:beta:*:*:*:*:*:*",
|
|
"matchCriteriaId": "5B2E0E16-AC01-4D34-A145-1510DA0DE4F9"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:7-zip:7-zip:4.47:beta:*:*:*:*:*:*",
|
|
"matchCriteriaId": "53C18BF5-D237-4BBE-B008-84C2CF81FBAF"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:7-zip:7-zip:4.48:beta:*:*:*:*:*:*",
|
|
"matchCriteriaId": "0AC41507-1413-4224-8DCB-B96469087564"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:7-zip:7-zip:4.49:beta:*:*:*:*:*:*",
|
|
"matchCriteriaId": "6BB31556-1D8C-4C98-9013-605DE461FB1F"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:7-zip:7-zip:4.50:beta:*:*:*:*:*:*",
|
|
"matchCriteriaId": "0F0851E8-0C8A-48C6-B519-1A2CFD500B8A"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:7-zip:7-zip:4.51:beta:*:*:*:*:*:*",
|
|
"matchCriteriaId": "56A6D1EC-4605-43F0-9290-380168627D5F"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:7-zip:7-zip:4.52:beta:*:*:*:*:*:*",
|
|
"matchCriteriaId": "56A4F4D2-C4E7-4240-8938-C695586CFE93"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"references": [
|
|
{
|
|
"url": "http://akky.cjb.net/security/7-zip3.txt",
|
|
"source": "cve@mitre.org",
|
|
"tags": [
|
|
"Broken Link"
|
|
]
|
|
},
|
|
{
|
|
"url": "http://jvn.jp/jp/JVN%2362868899/index.html",
|
|
"source": "cve@mitre.org",
|
|
"tags": [
|
|
"Third Party Advisory"
|
|
]
|
|
},
|
|
{
|
|
"url": "http://osvdb.org/40482",
|
|
"source": "cve@mitre.org",
|
|
"tags": [
|
|
"Broken Link"
|
|
]
|
|
},
|
|
{
|
|
"url": "http://secunia.com/advisories/26624",
|
|
"source": "cve@mitre.org",
|
|
"tags": [
|
|
"Third Party Advisory"
|
|
]
|
|
},
|
|
{
|
|
"url": "http://sourceforge.net/project/shownotes.php?release_id=535160&group_id=14481",
|
|
"source": "cve@mitre.org",
|
|
"tags": [
|
|
"Product",
|
|
"Third Party Advisory"
|
|
]
|
|
},
|
|
{
|
|
"url": "http://www.securityfocus.com/bid/25545",
|
|
"source": "cve@mitre.org",
|
|
"tags": [
|
|
"Third Party Advisory",
|
|
"VDB Entry"
|
|
]
|
|
},
|
|
{
|
|
"url": "http://www.vupen.com/english/advisories/2007/3086",
|
|
"source": "cve@mitre.org",
|
|
"tags": [
|
|
"Third Party Advisory"
|
|
]
|
|
},
|
|
{
|
|
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/36459",
|
|
"source": "cve@mitre.org",
|
|
"tags": [
|
|
"Third Party Advisory",
|
|
"VDB Entry"
|
|
]
|
|
}
|
|
]
|
|
} |