CVE-2005-2856
Detail
Deferred
This CVE record is not being prioritized for NVD enrichment efforts due to resource or other concerns.
Current Description
Stack-based buffer overflow in the WinACE UNACEV2.DLL third-party compression utility before 2.6.0.0, as used in multiple products including (1) ALZip 5.51 through 6.11, (2) Servant Salamander 2.0 and 2.5 Beta 1, (3) WinHKI 1.66 and 1.67, (4) ExtractNow 3.x, (5) Total Commander 6.53, (6) Anti-Trojan 5.5.421, (7) PowerArchiver before 9.61, (8) UltimateZip 2.7,1, 3.0.3, and 3.1b, (9) Where Is It (WhereIsIt) 3.73.501, (10) FilZip 3.04, (11) IZArc 3.5 beta3, (12) Eazel 1.0, (13) Rising Antivirus 18.27.21 and earlier, (14) AutoMate 6.1.0.0, (15) BitZipper 4.1 SR-1, (16) ZipTV, and other products, allows user-assisted attackers to execute arbitrary code via a long filename in an ACE archive.
View Analysis Description
Analysis
Description
Stack-based buffer overflow in the WinACE UNACEV2.DLL third-party compression utility before 2.6.0.0, as used in multiple products including (1) ALZip 5.51 through 6.11, (2) Servant Salamander 2.0 and 2.5 Beta 1, (3) WinHKI 1.66 and 1.67, (4) ExtractNow 3.x, (5) Total Commander 6.53, (6) Anti-Trojan 5.5.421, (7) PowerArchiver before 9.61, (8) UltimateZip 2.7,1, 3.0.3, and 3.1b, (9) Where Is It (WhereIsIt) 3.73.501, (10) FilZip 3.04, (11) IZArc 3.5 beta3, (12) Eazel 1.0, (13) Rising Antivirus 18.27.21 and earlier, (14) AutoMate 6.1.0.0, (15) BitZipper 4.1 SR-1, and other products, allows user-assisted attackers to execute arbitrary code via a long filename in an ACE archive.
Metrics
CVSS Version 4.0
CVSS Version 3.x
CVSS Version 2.0
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
CVSS 4.0 Severity and Vector Strings:
NVD assessment
not yet provided.
CVSS 3.x Severity and Vector Strings:
NVD assessment
not yet provided.
CVSS 2.0 Severity and Vector Strings:
Vector:
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [email protected] .
URL
Source(s)
Tag(s)
http://marc.info/?l=bugtraq&m=112621008228458&w=2
CVE, MITRE
http://secunia.com/advisories/16479
CVE, MITRE
Patch
Vendor Advisory
http://secunia.com/advisories/19454
CVE, MITRE
Vendor Advisory
http://secunia.com/advisories/19458
CVE, MITRE
Vendor Advisory
http://secunia.com/advisories/19581
CVE, MITRE
Vendor Advisory
http://secunia.com/advisories/19596
CVE, MITRE
http://secunia.com/advisories/19612
CVE, MITRE
http://secunia.com/advisories/19834
CVE, MITRE
Vendor Advisory
http://secunia.com/advisories/19890
CVE, MITRE
Vendor Advisory
http://secunia.com/advisories/19931
CVE, MITRE
http://secunia.com/advisories/19938
CVE, MITRE
Vendor Advisory
http://secunia.com/advisories/19939
CVE, MITRE
http://secunia.com/advisories/19967
CVE, MITRE
Vendor Advisory
http://secunia.com/advisories/19975
CVE, MITRE
Vendor Advisory
http://secunia.com/advisories/19977
CVE, MITRE
Vendor Advisory
http://secunia.com/advisories/20009
CVE, MITRE
Vendor Advisory
http://secunia.com/advisories/20270
CVE, MITRE
http://secunia.com/secunia_research/2005-41/advisory/
CVE, MITRE
http://secunia.com/secunia_research/2006-24/advisory
CVE, MITRE
Vendor Advisory
http://secunia.com/secunia_research/2006-25/advisory
CVE, MITRE
Vendor Advisory
http://secunia.com/secunia_research/2006-27/
CVE, MITRE
Vendor Advisory
http://secunia.com/secunia_research/2006-28/advisory
CVE, MITRE
Vendor Advisory
http://secunia.com/secunia_research/2006-29/advisory/
CVE, MITRE
Vendor Advisory
http://secunia.com/secunia_research/2006-30/advisory
CVE, MITRE
Vendor Advisory
http://secunia.com/secunia_research/2006-32/advisory/
CVE, MITRE
http://secunia.com/secunia_research/2006-33/advisory/
CVE, MITRE
Vendor Advisory
http://secunia.com/secunia_research/2006-36/advisory
CVE, MITRE
Vendor Advisory
http://secunia.com/secunia_research/2006-38/advisory
CVE, MITRE
Vendor Advisory
http://secunia.com/secunia_research/2006-46/advisory/
CVE, MITRE
http://secunia.com/secunia_research/2006-50/advisory/
CVE, MITRE
http://securityreason.com/securityalert/49
CVE, MITRE
http://securitytracker.com/id?1014863
CVE, MITRE
http://securitytracker.com/id?1015852
CVE, MITRE
http://securitytracker.com/id?1016011
CVE, MITRE
http://securitytracker.com/id?1016012
CVE, MITRE
http://securitytracker.com/id?1016065
CVE, MITRE
http://securitytracker.com/id?1016066
CVE, MITRE
http://securitytracker.com/id?1016088
CVE, MITRE
http://securitytracker.com/id?1016114
CVE, MITRE
http://securitytracker.com/id?1016115
CVE, MITRE
http://securitytracker.com/id?1016177
CVE, MITRE
http://securitytracker.com/id?1016257
CVE, MITRE
http://securitytracker.com/id?1016512
CVE, MITRE
http://www.osvdb.org/25129
CVE, MITRE
http://www.securityfocus.com/archive/1/432357/100/0/threaded
CVE, MITRE
http://www.securityfocus.com/archive/1/432579/100/0/threaded
CVE, MITRE
http://www.securityfocus.com/archive/1/433258/100/0/threaded
CVE, MITRE
http://www.securityfocus.com/archive/1/433352/100/0/threaded
CVE, MITRE
http://www.securityfocus.com/archive/1/433693/100/0/threaded
CVE, MITRE
http://www.securityfocus.com/archive/1/434011/100/0/threaded
CVE, MITRE
http://www.securityfocus.com/archive/1/434234/100/0/threaded
CVE, MITRE
http://www.securityfocus.com/archive/1/434279/100/0/threaded
CVE, MITRE
http://www.securityfocus.com/archive/1/436639/100/0/threaded
CVE, MITRE
http://www.securityfocus.com/archive/1/440303/100/0/threaded
CVE, MITRE
http://www.securityfocus.com/bid/14759
CVE, MITRE
http://www.securityfocus.com/bid/19884
CVE, MITRE
http://www.vupen.com/english/advisories/2006/1565
CVE, MITRE
http://www.vupen.com/english/advisories/2006/1577
CVE, MITRE
http://www.vupen.com/english/advisories/2006/1611
CVE, MITRE
http://www.vupen.com/english/advisories/2006/1681
CVE, MITRE
http://www.vupen.com/english/advisories/2006/1694
CVE, MITRE
http://www.vupen.com/english/advisories/2006/1725
CVE, MITRE
http://www.vupen.com/english/advisories/2006/1775
CVE, MITRE
http://www.vupen.com/english/advisories/2006/1797
CVE, MITRE
http://www.vupen.com/english/advisories/2006/1835
CVE, MITRE
http://www.vupen.com/english/advisories/2006/1836
CVE, MITRE
http://www.vupen.com/english/advisories/2006/2047
CVE, MITRE
http://www.vupen.com/english/advisories/2006/2184
CVE, MITRE
http://www.vupen.com/english/advisories/2006/2824
CVE, MITRE
http://www.vupen.com/english/advisories/2006/3495
CVE, MITRE
https://exchange.xforce.ibmcloud.com/vulnerabilities/26116
CVE, MITRE
https://exchange.xforce.ibmcloud.com/vulnerabilities/26142
CVE, MITRE
https://exchange.xforce.ibmcloud.com/vulnerabilities/26168
CVE, MITRE
https://exchange.xforce.ibmcloud.com/vulnerabilities/26272
CVE, MITRE
https://exchange.xforce.ibmcloud.com/vulnerabilities/26302
CVE, MITRE
https://exchange.xforce.ibmcloud.com/vulnerabilities/26315
CVE, MITRE
https://exchange.xforce.ibmcloud.com/vulnerabilities/26385
CVE, MITRE
https://exchange.xforce.ibmcloud.com/vulnerabilities/26447
CVE, MITRE
https://exchange.xforce.ibmcloud.com/vulnerabilities/26479
CVE, MITRE
https://exchange.xforce.ibmcloud.com/vulnerabilities/26480
CVE, MITRE
https://exchange.xforce.ibmcloud.com/vulnerabilities/26736
CVE, MITRE
https://exchange.xforce.ibmcloud.com/vulnerabilities/26982
CVE, MITRE
https://exchange.xforce.ibmcloud.com/vulnerabilities/27763
CVE, MITRE
https://exchange.xforce.ibmcloud.com/vulnerabilities/28787
CVE, MITRE
Weakness Enumeration
CWE-ID
CWE Name
Source
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
NIST  
Change History
6 change records found show changes
CVE Modified by CVE 11/20/2024 7:00:34 PM
Action
Type
Old Value
New Value
Added
Reference
http://marc.info/?l=bugtraq&m=112621008228458&w=2
Added
Reference
http://secunia.com/advisories/16479
Added
Reference
http://secunia.com/advisories/19454
Added
Reference
http://secunia.com/advisories/19458
Added
Reference
http://secunia.com/advisories/19581
Added
Reference
http://secunia.com/advisories/19596
Added
Reference
http://secunia.com/advisories/19612
Added
Reference
http://secunia.com/advisories/19834
Added
Reference
http://secunia.com/advisories/19890
Added
Reference
http://secunia.com/advisories/19931
Added
Reference
http://secunia.com/advisories/19938
Added
Reference
http://secunia.com/advisories/19939
Added
Reference
http://secunia.com/advisories/19967
Added
Reference
http://secunia.com/advisories/19975
Added
Reference
http://secunia.com/advisories/19977
Added
Reference
http://secunia.com/advisories/20009
Added
Reference
http://secunia.com/advisories/20270
Added
Reference
http://secunia.com/secunia_research/2005-41/advisory/
Added
Reference
http://secunia.com/secunia_research/2006-24/advisory
Added
Reference
http://secunia.com/secunia_research/2006-25/advisory
Added
Reference
http://secunia.com/secunia_research/2006-27/
Added
Reference
http://secunia.com/secunia_research/2006-28/advisory
Added
Reference
http://secunia.com/secunia_research/2006-29/advisory/
Added
Reference
http://secunia.com/secunia_research/2006-30/advisory
Added
Reference
http://secunia.com/secunia_research/2006-32/advisory/
Added
Reference
http://secunia.com/secunia_research/2006-33/advisory/
Added
Reference
http://secunia.com/secunia_research/2006-36/advisory
Added
Reference
http://secunia.com/secunia_research/2006-38/advisory
Added
Reference
http://secunia.com/secunia_research/2006-46/advisory/
Added
Reference
http://secunia.com/secunia_research/2006-50/advisory/
Added
Reference
http://securityreason.com/securityalert/49
Added
Reference
http://securitytracker.com/id?1014863
Added
Reference
http://securitytracker.com/id?1015852
Added
Reference
http://securitytracker.com/id?1016011
Added
Reference
http://securitytracker.com/id?1016012
Added
Reference
http://securitytracker.com/id?1016065
Added
Reference
http://securitytracker.com/id?1016066
Added
Reference
http://securitytracker.com/id?1016088
Added
Reference
http://securitytracker.com/id?1016114
Added
Reference
http://securitytracker.com/id?1016115
Added
Reference
http://securitytracker.com/id?1016177
Added
Reference
http://securitytracker.com/id?1016257
Added
Reference
http://securitytracker.com/id?1016512
Added
Reference
http://www.osvdb.org/25129
Added
Reference
http://www.securityfocus.com/archive/1/432357/100/0/threaded
Added
Reference
http://www.securityfocus.com/archive/1/432579/100/0/threaded
Added
Reference
http://www.securityfocus.com/archive/1/433258/100/0/threaded
Added
Reference
http://www.securityfocus.com/archive/1/433352/100/0/threaded
Added
Reference
http://www.securityfocus.com/archive/1/433693/100/0/threaded
Added
Reference
http://www.securityfocus.com/archive/1/434011/100/0/threaded
Added
Reference
http://www.securityfocus.com/archive/1/434234/100/0/threaded
Added
Reference
http://www.securityfocus.com/archive/1/434279/100/0/threaded
Added
Reference
http://www.securityfocus.com/archive/1/436639/100/0/threaded
Added
Reference
http://www.securityfocus.com/archive/1/440303/100/0/threaded
Added
Reference
http://www.securityfocus.com/bid/14759
Added
Reference
http://www.securityfocus.com/bid/19884
Added
Reference
http://www.vupen.com/english/advisories/2006/1565
Added
Reference
http://www.vupen.com/english/advisories/2006/1577
Added
Reference
http://www.vupen.com/english/advisories/2006/1611
Added
Reference
http://www.vupen.com/english/advisories/2006/1681
Added
Reference
http://www.vupen.com/english/advisories/2006/1694
Added
Reference
http://www.vupen.com/english/advisories/2006/1725
Added
Reference
http://www.vupen.com/english/advisories/2006/1775
Added
Reference
http://www.vupen.com/english/advisories/2006/1797
Added
Reference
http://www.vupen.com/english/advisories/2006/1835
Added
Reference
http://www.vupen.com/english/advisories/2006/1836
Added
Reference
http://www.vupen.com/english/advisories/2006/2047
Added
Reference
http://www.vupen.com/english/advisories/2006/2184
Added
Reference
http://www.vupen.com/english/advisories/2006/2824
Added
Reference
http://www.vupen.com/english/advisories/2006/3495
Added
Reference
https://exchange.xforce.ibmcloud.com/vulnerabilities/26116
Added
Reference
https://exchange.xforce.ibmcloud.com/vulnerabilities/26142
Added
Reference
https://exchange.xforce.ibmcloud.com/vulnerabilities/26168
Added
Reference
https://exchange.xforce.ibmcloud.com/vulnerabilities/26272
Added
Reference
https://exchange.xforce.ibmcloud.com/vulnerabilities/26302
Added
Reference
https://exchange.xforce.ibmcloud.com/vulnerabilities/26315
Added
Reference
https://exchange.xforce.ibmcloud.com/vulnerabilities/26385
Added
Reference
https://exchange.xforce.ibmcloud.com/vulnerabilities/26447
Added
Reference
https://exchange.xforce.ibmcloud.com/vulnerabilities/26479
Added
Reference
https://exchange.xforce.ibmcloud.com/vulnerabilities/26480
Added
Reference
https://exchange.xforce.ibmcloud.com/vulnerabilities/26736
Added
Reference
https://exchange.xforce.ibmcloud.com/vulnerabilities/26982
Added
Reference
https://exchange.xforce.ibmcloud.com/vulnerabilities/27763
Added
Reference
https://exchange.xforce.ibmcloud.com/vulnerabilities/28787
CVE Modified by MITRE 5/13/2024 9:31:33 PM
Action
Type
Old Value
New Value
CVE Modified by MITRE 10/19/2018 11:33:53 AM
Action
Type
Old Value
New Value
Added
Reference
http://www.securityfocus.com/archive/1/432357/100/0/threaded [No Types Assigned]
Added
Reference
http://www.securityfocus.com/archive/1/432579/100/0/threaded [No Types Assigned]
Added
Reference
http://www.securityfocus.com/archive/1/433258/100/0/threaded [No Types Assigned]
Added
Reference
http://www.securityfocus.com/archive/1/433352/100/0/threaded [No Types Assigned]
Added
Reference
http://www.securityfocus.com/archive/1/433693/100/0/threaded [No Types Assigned]
Added
Reference
http://www.securityfocus.com/archive/1/434011/100/0/threaded [No Types Assigned]
Added
Reference
http://www.securityfocus.com/archive/1/434234/100/0/threaded [No Types Assigned]
Added
Reference
http://www.securityfocus.com/archive/1/434279/100/0/threaded [No Types Assigned]
Added
Reference
http://www.securityfocus.com/archive/1/436639/100/0/threaded [No Types Assigned]
Added
Reference
http://www.securityfocus.com/archive/1/440303/100/0/threaded [No Types Assigned]
Removed
Reference
http://www.securityfocus.com/archive/1/archive/1/432357/100/0/threaded [No Types Assigned]
Removed
Reference
http://www.securityfocus.com/archive/1/archive/1/432579/100/0/threaded [No Types Assigned]
Removed
Reference
http://www.securityfocus.com/archive/1/archive/1/433258/100/0/threaded [No Types Assigned]
Removed
Reference
http://www.securityfocus.com/archive/1/archive/1/433352/100/0/threaded [No Types Assigned]
Removed
Reference
http://www.securityfocus.com/archive/1/archive/1/433693/100/0/threaded [No Types Assigned]
Removed
Reference
http://www.securityfocus.com/archive/1/archive/1/434011/100/0/threaded [No Types Assigned]
Removed
Reference
http://www.securityfocus.com/archive/1/archive/1/434234/100/0/threaded [No Types Assigned]
Removed
Reference
http://www.securityfocus.com/archive/1/archive/1/434279/100/0/threaded [No Types Assigned]
Removed
Reference
http://www.securityfocus.com/archive/1/archive/1/436639/100/0/threaded [No Types Assigned]
Removed
Reference
http://www.securityfocus.com/archive/1/archive/1/440303/100/0/threaded [No Types Assigned]
CVE Modified by MITRE 7/10/2017 9:33:01 PM
Action
Type
Old Value
New Value
Added
Reference
https://exchange.xforce.ibmcloud.com/vulnerabilities/26116 [No Types Assigned]
Added
Reference
https://exchange.xforce.ibmcloud.com/vulnerabilities/26142 [No Types Assigned]
Added
Reference
https://exchange.xforce.ibmcloud.com/vulnerabilities/26168 [No Types Assigned]
Added
Reference
https://exchange.xforce.ibmcloud.com/vulnerabilities/26272 [No Types Assigned]
Added
Reference
https://exchange.xforce.ibmcloud.com/vulnerabilities/26302 [No Types Assigned]
Added
Reference
https://exchange.xforce.ibmcloud.com/vulnerabilities/26315 [No Types Assigned]
Added
Reference
https://exchange.xforce.ibmcloud.com/vulnerabilities/26385 [No Types Assigned]
Added
Reference
https://exchange.xforce.ibmcloud.com/vulnerabilities/26447 [No Types Assigned]
Added
Reference
https://exchange.xforce.ibmcloud.com/vulnerabilities/26479 [No Types Assigned]
Added
Reference
https://exchange.xforce.ibmcloud.com/vulnerabilities/26480 [No Types Assigned]
Added
Reference
https://exchange.xforce.ibmcloud.com/vulnerabilities/26736 [No Types Assigned]
Added
Reference
https://exchange.xforce.ibmcloud.com/vulnerabilities/26982 [No Types Assigned]
Added
Reference
https://exchange.xforce.ibmcloud.com/vulnerabilities/27763 [No Types Assigned]
Added
Reference
https://exchange.xforce.ibmcloud.com/vulnerabilities/28787 [No Types Assigned]
Removed
Reference
http://xforce.iss.net/xforce/xfdb/26116 [No Types Assigned]
Removed
Reference
http://xforce.iss.net/xforce/xfdb/26142 [No Types Assigned]
Removed
Reference
http://xforce.iss.net/xforce/xfdb/26168 [No Types Assigned]
Removed
Reference
http://xforce.iss.net/xforce/xfdb/26272 [No Types Assigned]
Removed
Reference
http://xforce.iss.net/xforce/xfdb/26302 [No Types Assigned]
Removed
Reference
http://xforce.iss.net/xforce/xfdb/26315 [No Types Assigned]
Removed
Reference
http://xforce.iss.net/xforce/xfdb/26385 [No Types Assigned]
Removed
Reference
http://xforce.iss.net/xforce/xfdb/26447 [No Types Assigned]
Removed
Reference
http://xforce.iss.net/xforce/xfdb/26479 [No Types Assigned]
Removed
Reference
http://xforce.iss.net/xforce/xfdb/26480 [No Types Assigned]
Removed
Reference
http://xforce.iss.net/xforce/xfdb/26736 [No Types Assigned]
Removed
Reference
http://xforce.iss.net/xforce/xfdb/26982 [No Types Assigned]
Removed
Reference
http://xforce.iss.net/xforce/xfdb/27763 [No Types Assigned]
Removed
Reference
http://xforce.iss.net/xforce/xfdb/28787 [No Types Assigned]
CVE Modified by MITRE 10/17/2016 11:30:52 PM
Action
Type
Old Value
New Value
Added
Reference
http://marc.info/?l=bugtraq&m=112621008228458&w=2
Removed
Reference
http://marc.theaimsgroup.com/?l=bugtraq&m=112621008228458&w=2
Initial CVE Analysis 9/08/2005 11:06:00 AM
Action
Type
Old Value
New Value
Quick Info
CVE Dictionary Entry: CVE-2005-2856 NVD
Published Date: 09/08/2005 NVD
Last Modified: 04/02/2025
Source: MITRE