CVE Database
/

CVE-2008-4420

Back to search

CVE-2008-4420

Published: Apr 13, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple stack-based buffer overflows in DZIP32.DLL before 5.0.0.8 in DynaZip Max and DZIPS32.DLL before 6.0.0.5 in DynaZip Max Secure; as used in HP OpenView Performance Agent C.04.60, HP Performance Agent C.04.70 and C.04.72, TurboZIP 6.0, and other products; allow user-assisted attackers to execute arbitrary code via a long filename in a ZIP archive during a (1) Fix (aka Repair), (2) Add, (3) Update, or (4) Freshen action, a related issue to CVE-2006-3985.

VendorProductVersions

n/a

n/a

affected
n/a

References

1022021
vdb-entry
x_refsource_SECTRACK
19143
vdb-entry
x_refsource_BID
HPSBMA02396
vendor-advisory
x_refsource_HP
53478
vdb-entry
x_refsource_OSVDB
21180
third-party-advisory
x_refsource_SECUNIA
ADV-2006-2957
vdb-entry
x_refsource_VUPEN
34659
third-party-advisory
x_refsource_SECUNIA
SSRT080175
vendor-advisory
x_refsource_HP
ADV-2009-0980
vdb-entry
x_refsource_VUPEN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now