Winace ARJ File Handling Buffer Overflow Vulnerability
BID:16786
Info
Winace ARJ File Handling Buffer Overflow Vulnerability
| Bugtraq ID: | 16786 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-0813 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 23 2006 12:00AM |
| Updated: | Feb 24 2006 05:52PM |
| Credit: | Discovered by Tan Chew Keong. |
| Vulnerable: |
Winace Winace 2.60 |
| Not Vulnerable: | |
Discussion
Winace ARJ File Handling Buffer Overflow Vulnerability
Winace is prone to a buffer-overflow vulnerability when handling malformed ARJ archives. Successful exploitation could result in an application crash or potential arbitrary code execution.
Winace 2.60 is affected by this issue. Earlier versions may also be vulnerable.
Winace is prone to a buffer-overflow vulnerability when handling malformed ARJ archives. Successful exploitation could result in an application crash or potential arbitrary code execution.
Winace 2.60 is affected by this issue. Earlier versions may also be vulnerable.
Exploit / POC
Winace ARJ File Handling Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Winace ARJ File Handling Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected]
This issue will reportedly be fixed in Winace 2.61, but this version does not yet appear to be available.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected]
This issue will reportedly be fixed in Winace 2.61, but this version does not yet appear to be available.
References
Winace ARJ File Handling Buffer Overflow Vulnerability
References:
References:
- Winace Homepage (Winace)
- Secunia Research: WinACE ARJ Archive Handling Buffer Overflow (Secunia Research
)