CVE-2010-5300
medium · 6.8Stack-based buffer overflow in Jzip 1.3 through 2.0.0.132900 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long file name in a zip archive.
6.8
CVSS
14.6%
EPSS (exploit prob.)
96th
EPSS percentile
2014-06-11
Published
AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| jzip | jzip | 1.3 |
| jzip | jzip | 2.0.0.132900 |
Check a specific version with /api/v1/cve/match.
References
- http://osvdb.org/show/osvdb/65041
- http://packetstormsecurity.com/files/126216/Jzip-2.0.0.132900-Buffer-Overflow.html
- http://seclists.org/fulldisclosure/2010/Apr/79
- http://www.exploit-db.com/exploits/32899
- https://www.corelan.be/index.php/forum/security-advisories-archive-2010/corelan-10-021-jzip-zip-seh-bof
- http://osvdb.org/show/osvdb/65041
- http://packetstormsecurity.com/files/126216/Jzip-2.0.0.132900-Buffer-Overflow.html
- http://seclists.org/fulldisclosure/2010/Apr/79
- http://www.exploit-db.com/exploits/32899
- https://www.corelan.be/index.php/forum/security-advisories-archive-2010/corelan-10-021-jzip-zip-seh-bof
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2010-5300