WinZip Multiple Unspecified Buffer Overflow Vulnerabilities
BID:11092
Info
WinZip Multiple Unspecified Buffer Overflow Vulnerabilities
| Bugtraq ID: | 11092 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-1465 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Sep 01 2004 12:00AM |
| Updated: | Jul 12 2009 07:06AM |
| Credit: | These issues were disclosed by the vendor. |
| Vulnerable: |
WinZip WinZip 9.0 WinZip WinZip 8.1 SR-1 WinZip WinZip 8.1 WinZip WinZip 8.0 WinZip WinZip 7.0 |
| Not Vulnerable: |
WinZip WinZip 9.0 SR-1 |
Discussion
WinZip Multiple Unspecified Buffer Overflow Vulnerabilities
WinZip is reported prone to multiple unspecified buffer overflow vulnerabilities. These issues may allow a remote or local attacker to potentially execute arbitrary code on a vulnerable computer. A successful attack may allow an attacker to gain unauthorized access to a computer. The problems likely occur due to insufficient bounds checking when processing zip archives.
A local buffer overflow vulnerability was reported as well. This issue can be triggered through the command line.
WinZip versions 9.0 and prior are affected by these issues.
Due to a lack of details, further information is not available at the moment. This BID will be updated as more information becomes available.
WinZip is reported prone to multiple unspecified buffer overflow vulnerabilities. These issues may allow a remote or local attacker to potentially execute arbitrary code on a vulnerable computer. A successful attack may allow an attacker to gain unauthorized access to a computer. The problems likely occur due to insufficient bounds checking when processing zip archives.
A local buffer overflow vulnerability was reported as well. This issue can be triggered through the command line.
WinZip versions 9.0 and prior are affected by these issues.
Due to a lack of details, further information is not available at the moment. This BID will be updated as more information becomes available.
Exploit / POC
WinZip Multiple Unspecified Buffer Overflow Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
WinZip Multiple Unspecified Buffer Overflow Vulnerabilities
Solution:
The vendor has released WinZip 9.0 SR-1 to address these issues.
Solution:
The vendor has released WinZip 9.0 SR-1 to address these issues.
References
WinZip Multiple Unspecified Buffer Overflow Vulnerabilities
References:
References:
- WinZip 9.0 Service Release 1 (SR-1) (WinZip)
- WinZip Homepage (WinZip)