CVE-2005-2856 EXPLOIT
Patch early
A public exploit exists.
Description
Stack-based buffer overflow in the WinACE UNACEV2.DLL third-party compression utility before 2.6.0.0, as used in multiple products including (1) ALZip 5.51 through 6.11, (2) Servant Salamander 2.0 and 2.5 Beta 1, (3) WinHKI 1.66 and 1.67, (4) ExtractNow 3.x, (5) Total Commander 6.53, (6) Anti-Trojan 5.5.421, (7) PowerArchiver before 9.61, (8) UltimateZip 2.7,1, 3.0.3, and 3.1b, (9) Where Is It (WhereIsIt) 3.73.501, (10) FilZip 3.04, (11) IZArc 3.5 beta3, (12) Eazel 1.0, (13) Rising Antivirus 18.27.21 and earlier, (14) AutoMate 6.1.0.0, (15) BitZipper 4.1 SR-1, (16) ZipTV, and other products, allows user-assisted attackers to execute arbitrary code via a long filename in an ACE archive.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 15.68% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2005-09-08 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| winace | winace |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Total Commander 6.x - 'unacev2.dll' Buffer Overflow (PoC) | 2006-04-02 |
References
- http://marc.info/?l=bugtraq&m=112621008228458&w=2
- http://secunia.com/advisories/16479
- http://secunia.com/advisories/19454
- http://secunia.com/advisories/19458
- http://secunia.com/advisories/19581
- http://secunia.com/advisories/19596
- http://secunia.com/advisories/19612
- http://secunia.com/advisories/19834
- http://secunia.com/advisories/19890
- http://secunia.com/advisories/19931
- http://secunia.com/advisories/19938
- http://secunia.com/advisories/19939
- http://secunia.com/advisories/19967
- http://secunia.com/advisories/19975
- http://secunia.com/advisories/19977
- http://secunia.com/advisories/20009
- http://secunia.com/advisories/20270
- http://secunia.com/secunia_research/2005-41/advisory/
- http://secunia.com/secunia_research/2006-24/advisory
- http://secunia.com/secunia_research/2006-25/advisory
→ the Explorer · watch your stack · NVD