SpeedProject Multiple Products File Extraction Remote Buffer Overflow Vulnerabilities
BID:15554
Info
SpeedProject Multiple Products File Extraction Remote Buffer Overflow Vulnerabilities
| Bugtraq ID: | 15554 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 24 2005 12:00AM |
| Updated: | Nov 24 2005 12:00AM |
| Credit: | Discovery is credited to Tan Chew Keong, Secunia Research. |
| Vulnerable: |
Speedproject ZipStar 5.0 Build 4285 Speedproject Squeez 5.0 Build 4285 Speedproject SpeedCommander 11.0 Build 4430 Speedproject SpeedCommander 10.51 Build 4430 |
| Not Vulnerable: |
Speedproject ZipStar 5.10 Build 4460 Speedproject Squeez 5.0 Build 4460 Speedproject SpeedCommander 11.0 Build 4450 Speedproject SpeedCommander 10.52 Build 4450 |
Discussion
SpeedProject Multiple Products File Extraction Remote Buffer Overflow Vulnerabilities
Multiple products by SpeedProject are affected by remote buffer overflow vulnerabilities.
These issues arise when the applications handle malformed ZIP and UUE files.
Successful exploitation may result in arbitrary code execution in the context of the user who is running the application.
Multiple products by SpeedProject are affected by remote buffer overflow vulnerabilities.
These issues arise when the applications handle malformed ZIP and UUE files.
Successful exploitation may result in arbitrary code execution in the context of the user who is running the application.
Exploit / POC
SpeedProject Multiple Products File Extraction Remote Buffer Overflow Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
SpeedProject Multiple Products File Extraction Remote Buffer Overflow Vulnerabilities
Solution:
SpeedCommander 10.52 Build 4450, SpeedCommander 11.01 Build 4450, Squeez 5.10 Build 4460, and ZipStar 5.10 Build 4460 are not affected by these issues. Please contact the vendor to obtain fixes.
Solution:
SpeedCommander 10.52 Build 4450, SpeedCommander 11.01 Build 4450, Squeez 5.10 Build 4460, and ZipStar 5.10 Build 4460 are not affected by these issues. Please contact the vendor to obtain fixes.
References
SpeedProject Multiple Products File Extraction Remote Buffer Overflow Vulnerabilities
References:
References:
- Home Page (Speedproject)
- Secunia Research: SpeedProject Products ZIP/UUE File Extraction Buffer Overflow (Secunia Research
)