First published: Mon Apr 13 2009(Updated: )
Multiple stack-based buffer overflows in DZIP32.DLL before 5.0.0.8 in DynaZip Max and DZIPS32.DLL before 6.0.0.5 in DynaZip Max Secure; as used in HP OpenView Performance Agent C.04.60, HP Performance Agent C.04.70 and C.04.72, TurboZIP 6.0, and other products; allow user-assisted attackers to execute arbitrary code via a long filename in a ZIP archive during a (1) Fix (aka Repair), (2) Add, (3) Update, or (4) Freshen action, a related issue to CVE-2006-3985.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Innermedia Dynazip Max Secure | <=6.0.0.4 | |
Innermedia Dynazip Max | <=5.0.0.7 | |
Filestream Turbozip | =6.0 | |
Microsoft Windows | ||
HP OpenView Performance Agent | =c.04.60 | |
HP OpenView Performance Agent | =c.04.70 | |
HP OpenView Performance Agent | =c.04.72 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4420 has a critical severity rating due to the potential for remote code execution via stack-based buffer overflows.
To mitigate CVE-2008-4420, update DZIP32.DLL to version 5.0.0.8 or later and DZIPS32.DLL to version 6.0.0.5 or later.
CVE-2008-4420 impacts DynaZip Max and DynaZip Max Secure, along with HP OpenView Performance Agent versions C.04.60, C.04.70, and C.04.72.
Exploiting CVE-2008-4420 can allow attackers to execute arbitrary code on the system, compromising its integrity.
If you cannot update to the patched versions, it is recommended to limit access to the vulnerable software and avoid the use of untrusted input.