CVE-2005-4667

Publication date 31 December 2005

Last updated 24 July 2024


Ubuntu priority

Buffer overflow in UnZip 5.50 and earlier allows user-assisted attackers to execute arbitrary code via a long filename command line argument. NOTE: since the overflow occurs in a non-setuid program, there are not many scenarios under which it poses a vulnerability, unless unzip is passed long arguments when it is invoked from other programs.

Status

Package Ubuntu Release Status
unzip 7.04 feisty
Fixed 5.52-6ubuntu4
6.10 edgy
Fixed 5.52-6ubuntu4
6.06 LTS dapper
Fixed 5.52-6ubuntu4

References

Related Ubuntu Security Notices (USN)

    • USN-248-1
    • unzip vulnerability
    • 15 February 2006

Other references