CVE-2008-4420
Multiple stack-based buffer overflows in DZIP32.DLL before 5.0.0.8 in DynaZip Max and DZIPS32.DLL before 6.0.0.5 in DynaZip Max Secure; as used in HP OpenView Performance Agent C.04.60, HP Performance Agent C.04.70 and C.04.72, TurboZIP 6.0, and other products; allow user-assisted attackers to execute arbitrary code via a long filename in a ZIP archive during a (1) Fix (aka Repair), (2) Add, (3) Update, or (4) Freshen action, a related issue to CVE-2006-3985.
Published:Apr 13, 2009
Last Modified:Apr 23, 2026
EPS:Apr 13, 2009
EPSS Score:0.06532
CVSS Score:9.3
Affected Products
Vendor
Product
Action
Vendor
Filestream
Product
Turbozip
Filestream
Turbozip
Vendor
Hp
Product
Openview Performance Agent
Hp
Openview Performance Agent
Vendor
Innermedia
Product
Dynazip Max
Innermedia
Dynazip Max
Vendor
Innermedia
Product
Dynazip Max Secure
Innermedia
Dynazip Max Secure
Vendor
Microsoft
Product
Windows
Microsoft
Windows
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
