{"api_version":"1","generated_at":"2026-07-23T09:49:30+00:00","cve":"CVE-2005-4438","urls":{"html":"https://cve.report/CVE-2005-4438","api":"https://cve.report/api/cve/CVE-2005-4438.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-4438","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-4438"},"summary":{"title":"CVE-2005-4438","description":"Heap-based buffer overflow in Dec2Rar.dll 3.2.14.3, as distributed in the Symantec Antivirus Library and used by various Symantec products, allows remote attackers to execute arbitrary code via RAR archives with sub-block headers that contain incorrect values in the length field.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-12-21 01:03:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/archive/1/419853/100/0/threaded","name":"http://www.securityfocus.com/archive/1/419853/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/18131","name":"http://secunia.com/advisories/18131","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - Symantec AntiVirus RAR Archive Decompression Buffer Overflow","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.rem0te.com/public/images/symc2.pdf","name":"http://www.rem0te.com/public/images/symc2.pdf","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"rem0te.com","mime":"application/pdf","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2005/3003","name":"http://www.vupen.com/english/advisories/2005/3003","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1015384","name":"http://securitytracker.com/id?1015384","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Symantec Anti Virus Library Buffer Overflows in Processing RAR Format Sub-Block Header Length Values Let Remote Users Execute Arbitrary Code","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/15971","name":"http://www.securityfocus.com/bid/15971","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Symantec Antivirus Library RAR Decompression Heap Overflow Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.kb.cert.org/vuls/id/305272","name":"http://www.kb.cert.org/vuls/id/305272","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Vulnerability Note VU#305272","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/276","name":"http://securityreason.com/securityalert/276","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Symantec Antivirus Library Remote Heap Overflows - CXSecurity.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-4438","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-4438","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"4438","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"dec2rar.dll","cpe5":"dec2rar.dll","cpe6":"3.2.14.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T23:46:04.582Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"15971","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/15971"},{"name":"276","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/276"},{"name":"ADV-2005-3003","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2005/3003"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.rem0te.com/public/images/symc2.pdf"},{"name":"1015384","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1015384"},{"name":"20051220 Symantec Antivirus Library Remote Heap Overflows","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/419853/100/0/threaded"},{"name":"VU#305272","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/305272"},{"name":"18131","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/18131"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-12-20T00:00:00.000Z","descriptions":[{"lang":"en","value":"Heap-based buffer overflow in Dec2Rar.dll 3.2.14.3, as distributed in the Symantec Antivirus Library and used by various Symantec products, allows remote attackers to execute arbitrary code via RAR archives with sub-block headers that contain incorrect values in the length field."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-19T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"15971","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/15971"},{"name":"276","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/276"},{"name":"ADV-2005-3003","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2005/3003"},{"tags":["x_refsource_MISC"],"url":"http://www.rem0te.com/public/images/symc2.pdf"},{"name":"1015384","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1015384"},{"name":"20051220 Symantec Antivirus Library Remote Heap Overflows","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/419853/100/0/threaded"},{"name":"VU#305272","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/305272"},{"name":"18131","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/18131"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-4438","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Heap-based buffer overflow in Dec2Rar.dll 3.2.14.3, as distributed in the Symantec Antivirus Library and used by various Symantec products, allows remote attackers to execute arbitrary code via RAR archives with sub-block headers that contain incorrect values in the length field."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"15971","refsource":"BID","url":"http://www.securityfocus.com/bid/15971"},{"name":"276","refsource":"SREASON","url":"http://securityreason.com/securityalert/276"},{"name":"ADV-2005-3003","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2005/3003"},{"name":"http://www.rem0te.com/public/images/symc2.pdf","refsource":"MISC","url":"http://www.rem0te.com/public/images/symc2.pdf"},{"name":"1015384","refsource":"SECTRACK","url":"http://securitytracker.com/id?1015384"},{"name":"20051220 Symantec Antivirus Library Remote Heap Overflows","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/419853/100/0/threaded"},{"name":"VU#305272","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/305272"},{"name":"18131","refsource":"SECUNIA","url":"http://secunia.com/advisories/18131"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-4438","datePublished":"2005-12-21T01:00:00.000Z","dateReserved":"2005-12-21T00:00:00.000Z","dateUpdated":"2024-08-07T23:46:04.582Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-12-21 01:03:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":true,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:dec2rar.dll:dec2rar.dll:3.2.14.3:*:*:*:*:*:*:*","matchCriteriaId":"5EE46410-DDEE-48DF-BD25-C77902E62608"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"4438","Ordinal":"1","Title":"CVE-2005-4438","CVE":"CVE-2005-4438","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"4438","Ordinal":"1","NoteData":"Heap-based buffer overflow in Dec2Rar.dll 3.2.14.3, as distributed in the Symantec Antivirus Library and used by various Symantec products, allows remote attackers to execute arbitrary code via RAR archives with sub-block headers that contain incorrect values in the length field.","Type":"Description","Title":"CVE-2005-4438"},{"CveYear":"2005","CveId":"4438","Ordinal":"2","NoteData":"2005-12-20","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"4438","Ordinal":"3","NoteData":"2018-10-19","Type":"Other","Title":"Modified"}]}}}