CVE-2008-3871
UltraISO < 9.3.3.2685 - Remote Code Execution via DAA or ISZ Filename Format String
Title source: llmDescription
Multiple format string vulnerabilities in UltraISO 9.3.1.2633, and possibly other versions before 9.3.3.2685, allow user-assisted attackers to execute arbitrary code via format string specifiers in the filename of a (1) DAA or (2) ISZ file.
References (7)
Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1021965
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/502324/100/0/threaded
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/32415
Patch x_refsource_misc
http://www.ezbsystems.com/ultraiso/history.htm
Vendor Advisory x_refsource_misc
http://secunia.com/secunia_research/2008-48/
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/34325
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2009/0903
Scores
EPSS
0.0253
EPSS Percentile
82.8%
Details
CWE
CWE-134
Status
published
Products (1)
ezbsystems/ultraiso
9.3.1.2633
Published
Apr 01, 2009
Tracked Since
Feb 18, 2026