Directory traversal vulnerability in Unzoo 4.4-2 has unknown impact and attack vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| unzoo | unzoo | 4.4-2 |
unzoo.c, as used in multiple products including AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| avira | antivir | * |
| avast | avast_antivirus_home | 4.6.655 |
| avast | avast_antivirus_home | 4.7.1098 |
| avast | avast_antivirus | 4.6.394 |
| barracuda_networks | barracuda_spam_firewall | model_900 |
| avast | avast_antivirus_professional | 4.0 |
| avast | avast_antivirus_professional | 4.6 |
| avast | avast_antivirus_home | 4.0 |
| amavis | amavis | * |
| avast | avast_antivirus_home | 4.7.869 |
| avast | avast_antivirus_professional | 4.7.1043 |
| barracuda_networks | barracuda_spam_firewall | model_300 |
| unzoo | unzoo | 4.4 |
| avira | antivir_personal | 7 |
| avira | antivir | 7.04.00.23 |
| barracuda_networks | barracuda_spam_firewall | model_600 |
| avast | avast_antivirus_home | 4.6.691 |
| winace | winace | * |
| avast | avast_antivirus | 4.7.700 |
| barracuda_networks | barracuda_spam_firewall | model_800 |
| barracuda_networks | barracuda_spam_firewall | model_500 |
| avast | avast_antivirus_professional | 4.6.603 |
| avast | avast_antivirus_professional | 4.6.691 |
| rahul_dhesi | zoo | * |
| avast | avast_antivirus | 4.7.652 |
| avast | avast_antivirus_home | 4.7.827 |
| avast | avast_antivirus_professional | 4.6.665 |
| barracuda_networks | barracuda_spam_firewall | model_200 |
| panda | panda_antivirus | 2007 |
| avast | avast_antivirus_home | 4.6 |
| avast | avast_antivirus_home | 4.7.844 |
| picozip | picozip | * |
| avira | antivir | 6.35.00.00 |
| avast | avast_antivirus_professional | 4.7.1098 |
| avast | avast_antivirus_professional | 4.7.827 |
| avast | avast_antivirus_home | 4.7.1043 |
| barracuda_networks | barracuda_spam_firewall | * |
| avast | avast_antivirus_home | 4.6.665 |
| barracuda_networks | barracuda_spam_firewall | model_400 |
| avast | avast_antivirus_professional | 4.7.869 |
| barracuda_networks | barracuda_spam_firewall | model_100 |
| avira | antivir_personal | * |
| avast | avast_antivirus_home | 4.6.652 |
| panda | panda_antivirus_and_firewall | 2007 |
| avast | avast_antivirus_professional | 4.6.652 |
| avast | avast_antivirus_professional | 4.7.844 |
| avast | avast_antivirus | * |
Buffer overflow in the EntrReadArch function in unzoo might allow remote attackers to execute arbitrary code via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| unzoo | unzoo | * |
unzoo allows remote attackers to cause a denial of service (infinite loop and resource consumption) via unspecified vectors to the (1) ExtrArch or (2) ListArch function, related to pointer handling.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| unzoo | unzoo | - |