Hyper Estraier directory traversal/denial of service vulnerability


Hyper Estraier, a full text search system, contains a vulnerability in the process of creating index files.
CVSS Severity (What is CVSS?)

CVSS V2 Severity:
Base Metrics 4.3 (Medium) [IPA Score]
  • Access Vector: Network
  • Access Complexity: Medium
  • Authentication: None
  • Confidentiality Impact: Partial
  • Integrity Impact: None
  • Availability Impact: None
Affected Products

Mikio Hirabayashi
  • Hyper Estraier and earlier (Windows versions only)


If a remote attacker sends a specially crafted file and a user saves it in a search target directory, the attacker could register a file not to be searched in an index when the user creats an index, or cause a denial of service.

Vendor Information

Mikio Hirabayashi
CWE (What is CWE?)

CVE (What is CVE?)

  1. CVE-2005-3421

  1. JVN : JVN#18282718
  2. National Vulnerability Database (NVD) : CVE-2005-3421
  3. Secunia Advisory : SA17379
  4. SecurityFocus : 15236
  5. SecurityTracker : 1015119
Revision History

  • [2008/05/21]
      Web page published