CVE-2002-0370

Stuffit Expander < 7.0 - Buffer Overflow via Long Filename ZIP Entries

Title source: llm
STIX 2.1

Description

Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code via ZIP files containing entries with long filenames, including (1) Microsoft Windows 98 with Plus! Pack, (2) Windows XP, (3) Windows ME, (4) Lotus Notes R4 through R6 (pre-gold), (5) Verity KeyView, and (6) Stuffit Expander before 7.0.

References (9)

Core 9
Core References
Various Sources x_refsource_confirm
http://www.info-zip.org/FAQ.html
Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/10251.php
Third Party Advisory mailing-list x_refsource_vulnwatch
http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0009.html
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/587
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=103428193409223&w=2
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/383779
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/5873

Scores

EPSS 0.4330
EPSS Percentile 98.6%

Details

Status published
Products (18)
allume_systems_division/stuffit_expander 6.5.2
ibm/lotus_notes 5.0
ibm/lotus_notes 5.0.1
ibm/lotus_notes 5.0.2
ibm/lotus_notes 5.0.3
ibm/lotus_notes 5.0.4
ibm/lotus_notes 5.0.5
ibm/lotus_notes 5.0.9a
ibm/lotus_notes 5.0.10
ibm/lotus_notes 5.0.11
... and 8 more
Published Oct 10, 2002
Tracked Since Feb 18, 2026