CVE-2005-3051

Published: 09/24/2005 00:03:00
Stack-based buffer overflow in the ARJ plugin (arj.dll) 3.9.2.0 for 7-Zip 3.13, 4.23, and 4.26 BETA, as used in products including Turbo Searcher, allows remote attackers to execute arbitrary code via a large ARJ block.
HIGH
CVSS v2: 9.3

Status

DocFilters Release Package State Justification Comment
25.1 7-zip (23.01) False Positive Code Not Present Unknown vendors ‘igor_pavlov’
24.4 7-zip (23.01) False Positive Code Not Present Unknown vendors ‘igor_pavlov’
24.4.0 7-zip (23.01) False Positive Code Not Present Unknown vendors ‘igor_pavlov’
24.3 7-zip (23.01) False Positive Code Not Present Unknown vendors ‘igor_pavlov’
24.2.1 7-zip (23.01) False Positive Code Not Present Unknown vendors ‘igor_pavlov’
24.2 7-zip (23.01) False Positive Code Not Present Unknown vendors ‘igor_pavlov’
24.1 7-zip (23.01) False Positive Code Not Present Unknown vendors ‘igor_pavlov’
23.3 7-zip (23.01) False Positive Code Not Present Unknown vendors ‘igor_pavlov’
23.2.1 7-zip (17.01) Not Affected Protected At Runtime CVE does not included required value ‘lzma’
23.2 7-zip (17.01) Not Affected Protected At Runtime CVE does not included required value ‘lzma’
23.1 7-zip (17.01) Not Affected Protected At Runtime CVE does not included required value ‘lzma’
22.4 7-zip (17.01) Not Affected Protected At Runtime CVE does not included required value ‘lzma’

Severity score breakdown

References