CVE-2005-4667 describes a buffer overflow vulnerability in UnZip 5.50 and earlier, affecting the info-zip unzip product. This vulnerability allows user-assisted attackers to execute arbitrary code by providing an excessively long filename as a command-line argument. The severity is rated as low (CVSS 3.7), with a local attack vector and high access complexity, leading to partial confidentiality, integrity, and availability impacts. While there is no evidence of active exploitation or inclusion in the KEV catalog, exploit code is publicly available via ExploitDB, though community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.2CPE matchmatch criteria | cpe:2.3:a:info-zip:unzip:5.2:*:*:*:*:*:*:* | ||
5.3CPE matchmatch criteria | cpe:2.3:a:info-zip:unzip:5.3:*:*:*:*:*:*:* | ||
5.31CPE matchmatch criteria | cpe:2.3:a:info-zip:unzip:5.31:*:*:*:*:*:*:* | ||
5.32CPE matchmatch criteria | cpe:2.3:a:info-zip:unzip:5.32:*:*:*:*:*:*:* | ||
5.40CPE matchmatch criteria | cpe:2.3:a:info-zip:unzip:5.40:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:H/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.