CVE-2005-2856
Summary
| CVE | CVE-2005-2856 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-09-08 10:03:00 UTC |
| Updated | 2018-10-19 15:33:00 UTC |
| Description | Stack-based buffer overflow in the WinACE UNACEV2.DLL third-party compression utility before 2.6.0.0, as used in multiple products including (1) ALZip 5.51 through 6.11, (2) Servant Salamander 2.0 and 2.5 Beta 1, (3) WinHKI 1.66 and 1.67, (4) ExtractNow 3.x, (5) Total Commander 6.53, (6) Anti-Trojan 5.5.421, (7) PowerArchiver before 9.61, (8) UltimateZip 2.7,1, 3.0.3, and 3.1b, (9) Where Is It (WhereIsIt) 3.73.501, (10) FilZip 3.04, (11) IZArc 3.5 beta3, (12) Eazel 1.0, (13) Rising Antivirus 18.27.21 and earlier, (14) AutoMate 6.1.0.0, (15) BitZipper 4.1 SR-1, (16) ZipTV, and other products, allows user-assisted attackers to execute arbitrary code via a long filename in an ACE archive. |
Risk And Classification
Problem Types: CWE-119
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| AutoMate unacev2.dll Buffer Overflow Vulnerability - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| ZipTV ARJ Archive Handling and unacev2.dll Buffer Overflows - Advisories - Secunia | SECUNIA | secunia.com | |
| Where Is It unacev2.dll Buffer Overflow Vulnerability - Secunia Research - Secunia | MISC | secunia.com | Vendor Advisory |
| Secunia - Advisories - Total Commander unacev2.dll Buffer Overflow Vulnerability | SECUNIA | secunia.com | Vendor Advisory |
| BitZipper unacev2.dll Buffer Overflow Vulnerability - Secunia Research - Secunia | MISC | secunia.com | |
| About Secunia Research | Flexera | MISC | secunia.com | Vendor Advisory |
| UltimateZIP Buffer Overflow in Extracting ACE Archives Lets Remote Users Execute Arbitrary Code - SecurityTracker | SECTRACK | securitytracker.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| IZArc Buffer Overflow in 'unacev2.dll' in Processing ACE Archives Lets Remote Users Execute Arbitrary Code - SecurityTracker | SECTRACK | securitytracker.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Microchip Data Systems ZipTV TZipTV ARJ File Handling Buffer Overflow Vulnerability | BID | www.securityfocus.com | |
| ZipTV ARJ Archive Handling and unacev2.dll Buffer Overflows - Secunia Research - Secunia | MISC | secunia.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Anti-Trojan Buffer Overflow in 'unacev2.dll' in Processing ACE Archives Lets Remote Users Execute Arbitrary Code - SecurityTracker | SECTRACK | securitytracker.com | |
| Secunia - Advisories - Anti-Trojan unacev2.dll Buffer Overflow Vulnerability | SECUNIA | secunia.com | Vendor Advisory |
| IZArc unacev2.dll Buffer Overflow Vulnerability - Secunia Research - Secunia | MISC | secunia.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| BitZipper unacev2.dll Buffer Overflow Vulnerability - Advisories - Secunia | SECUNIA | secunia.com | |
| SecurityReason - ALZip Multiple Archive Handling Buffer Overflow | SREASON | securityreason.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Secunia - Advisories - FilZip unacev2.dll Buffer Overflow Vulnerability | SECUNIA | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| About Secunia Research | Flexera | MISC | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Eazel unacev2.dll Buffer Overflow Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | SECUNIA | secunia.com | Vendor Advisory |
| Secunia - Advisories - Servant Salamander unacev2.dll Buffer Overflow Vulnerability | SECUNIA | secunia.com | |
| About Secunia Research | Flexera | MISC | secunia.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| WinHKI Buffer Overflow in 'ztvunacev2.dll' Lets Remote Users Execute Arbitrary Code - SecurityTracker | SECTRACK | securitytracker.com | |
| Secunia - Secunia Research - Anti-Trojan unacev2.dll Buffer Overflow Vulnerability | MISC | secunia.com | Vendor Advisory |
| FilZip Buffer Overflow in 'unacev2.dll' in Processing ACE Archives Lets Remote Users Execute Arbitrary Code - SecurityTracker | SECTRACK | securitytracker.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| SecurityTracker.com Archives - Servant Salamander Buffer Overflow in 'unacev2.dll' Lets Remote Users Execute Arbitrary Code | SECTRACK | securitytracker.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| IZArc unacev2.dll Buffer Overflow Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | SECUNIA | secunia.com | Vendor Advisory |
| About Secunia Research | Flexera | MISC | secunia.com | Vendor Advisory |
| 25129 | OSVDB | www.osvdb.org | |
| About Secunia Research | Flexera | MISC | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Secunia - Advisories - ALZip ACE Archive Handling Buffer Overflow | SECUNIA | secunia.com | Patch, Vendor Advisory |
| SecurityTracker.com Archives - Rising Antivirus Stack Overflow in Scanning ACE Archives Lets Remote Users Execute Arbitrary Code | SECTRACK | securitytracker.com | |
| Multiple Vendor UNACEV2 Archive File Name Buffer Overflow Vulnerability | BID | www.securityfocus.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| About Secunia Research | Flexera | MISC | secunia.com | Vendor Advisory |
| Secunia - Advisories - UltimateZip unacev2.dll Buffer Overflow Vulnerability | SECUNIA | secunia.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Rising Antivirus unacev2.dll Buffer Overflow Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | SECUNIA | secunia.com | Vendor Advisory |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Total Commander Buffer Overflow UNACEV2.DLL Lets Remote Users Cause Arbitrary Code to Be Executed - SecurityTracker | SECTRACK | securitytracker.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Webmail- OVH | VUPEN | www.vupen.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| SecurityTracker.com Archives - AutoMate Buffer Overflow in 'unacev2.dll' Lets Remote Users Execute Arbitrary Code | SECTRACK | securitytracker.com | |
| WinHKI unacev2.dll Buffer Overflow Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | SECUNIA | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Secunia - Advisories - ExtractNow unacev2.dll Buffer Overflow Vulnerability | SECUNIA | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| ALZip Buffer Overflow UNACEV2.DLL Lets Remote Users Cause Arbitrary Code to Be Executed - SecurityTracker | SECTRACK | securitytracker.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| PowerArchiver unacev2.dll Buffer Overflow Vulnerability - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Where Is It unacev2.dll Buffer Overflow Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | SECUNIA | secunia.com | |
| About Secunia Research | Flexera | MISC | secunia.com | Vendor Advisory |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Eazel Buffer Overflow in 'ztvunacev2.dll' in Processing ACE Archives Lets Remote Users Execute Arbitrary Code - SecurityTracker | SECTRACK | securitytracker.com | |
| 'Secunia Research: ALZip ACE Archive Handling Buffer Overflow' - MARC | BUGTRAQ | marc.info | |
| SecurityTracker.com Archives - BitZipper Buffer Overflow in Processing ACE Archives Lets Remote Users Execute Arbitrary Code | SECTRACK | securitytracker.com | |
| FilZip unacev2.dll Buffer Overflow Vulnerability - Secunia Research - Secunia | MISC | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.