Back to Database
Status published
Medium
CVE-2008-3429
Buffer overflow in URI processing in HTTrack and WinHTTrack before...
Vulnerability Description
Buffer overflow in URI processing in HTTrack and WinHTTrack before 3.42-3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long URL.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-3429
Credits & Attribution
No credits recorded in the NVD database.
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44167
- http://www.httrack.com/history.txt
- http://www.vupen.com/english/advisories/2008/2221/references
- http://www.debian.org/security/2008/dsa-1626
- http://www.venustech.com.cn/NewsInfo/124/2032.Html
- http://secunia.com/advisories/31323/
- http://www.securityfocus.com/bid/30425
- https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00711.html
- https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00707.html
- http://secunia.com/advisories/31866
- http://secunia.com/advisories/31380
Affected Vendor
httrack
View all reports →Affected Software
httrack, winhttrack
Vulnerable Versions:
0.23, 0.24, 0.25, 0.99, 0.996, 0.997, 0.998, 1.00, 1.01, 1.02, 1.03, 1.04, 1.10, 1.11, 1.15, 1.16, 1.20, 1.21, 1.22, 1.23, 1.24, 1.30, 2.00, 2.01, 2.2, 2.02, 3.00, 3.01, 3.02, 3.03, 3.04, 3.05, 3.06, 3.07, 3.08, 3.09, 3.10, 3.15, 3.16, 3.20, 3.21, 3.22, 3.23, 3.30, 3.31, 3.32, 3.33, 3.40, 3.41, 3.42, 0
Timeline
Official Publish:
July 31st, 2008
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.