CVE-2005-4667

UnZip <5.50 - Buffer Overflow

Title source: llm

Description

Buffer overflow in UnZip 5.50 and earlier allows user-assisted attackers to execute arbitrary code via a long filename command line argument. NOTE: since the overflow occurs in a non-setuid program, there are not many scenarios under which it poses a vulnerability, unless unzip is passed long arguments when it is invoked from other programs.

Exploits (1)

exploitdb WORKING POC VERIFIED
by DVDMAN · cremotelinux
https://www.exploit-db.com/exploits/26913

Scores

EPSS 0.0313
EPSS Percentile 86.9%

Details

CWE
CWE-119
Status published
Products (8)
info-zip/unzip 5.2
info-zip/unzip 5.3
info-zip/unzip 5.31
info-zip/unzip 5.32
info-zip/unzip 5.40
info-zip/unzip 5.41
info-zip/unzip 5.42
info-zip/unzip 5.50
Published Dec 31, 2005
Tracked Since Feb 18, 2026