7.5

CVE-2005-4438

Heap-based buffer overflow in Dec2Rar.dll 3.2.14.3, as distributed in the Symantec Antivirus Library and used by various Symantec products, allows remote attackers to execute arbitrary code via RAR archives with sub-block headers that contain incorrect values in the length field.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dec2rar.DllDec2rar.Dll Version3.2.14.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.27% 0.927
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/18131
Vendor Advisory
http://securityreason.com/securityalert/276
http://securitytracker.com/id?1015384
http://www.kb.cert.org/vuls/id/305272
US Government Resource
http://www.rem0te.com/public/images/symc2.pdf
Vendor Advisory
http://www.securityfocus.com/archive/1/419853/100/0/threaded
http://www.securityfocus.com/bid/15971
http://www.vupen.com/english/advisories/2005/3003