CVE-2005-3317 describes multiple stack-based buffer overflows in ZipGenius versions before 6.0.2.1050. These vulnerabilities allow remote attackers to execute arbitrary code by crafting malicious archive files (ZIP, UUE/XXE/MIM, or ACE) containing excessively long filenames or original names. The vulnerability has a CVSS score of 7.5, indicating a high severity with a network-based attack vector, low attack complexity, and potential for partial confidentiality, integrity, and availability impact. While the EPSS score is low and it is not listed in CISA's KEV catalog, there is no known public exploit code (Metasploit, Nuclei, ExploitDB) or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= standard_6.0.2.1041CPE matchmatch criteria | cpe:2.3:a:zipgenius:zipgenius:*:*:*:*:*:*:*:* | ||
<= suite_6.0.2.1041CPE matchmatch criteria | cpe:2.3:a:zipgenius:zipgenius:*:*:*:*:*:*:*:* | ||
standard_5.5.1.468CPE matchmatch criteria | cpe:2.3:a:zipgenius:zipgenius:standard_5.5.1.468:*:*:*:*:*:*:* | ||
suite_5.5.1.468CPE matchmatch criteria | cpe:2.3:a:zipgenius:zipgenius:suite_5.5.1.468:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.