PicoZip Zipinfo.DLL Buffer Overflow Vulnerability
BID:18425
CVE-2006-2909 |Info
PicoZip Zipinfo.DLL Buffer Overflow Vulnerability
| Bugtraq ID: | 18425 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-2909 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 14 2006 12:00AM |
| Updated: | Jun 16 2006 06:41PM |
| Credit: | Tan Chew Keong of Secunia Research disclosed this vulnerability. |
| Vulnerable: |
PicoZip PicoZip 4.0.1 |
| Not Vulnerable: |
PicoZip PicoZip 4.0.2 |
Discussion
PicoZip Zipinfo.DLL Buffer Overflow Vulnerability
PicoZip is susceptible to a buffer-overflow vulnerability. The application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
This issue allows attackers to execute arbitrary machine code in the context of users running the affected application.
Version 4.0.1 of PicoZip is vulnerable to this issue; prior versions may also be affected.
PicoZip is susceptible to a buffer-overflow vulnerability. The application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
This issue allows attackers to execute arbitrary machine code in the context of users running the affected application.
Version 4.0.1 of PicoZip is vulnerable to this issue; prior versions may also be affected.
Exploit / POC
PicoZip Zipinfo.DLL Buffer Overflow Vulnerability
The following exploit is available to demonstrate this issue:
The following exploit is available to demonstrate this issue:
Solution / Fix
PicoZip Zipinfo.DLL Buffer Overflow Vulnerability
Solution:
The vendor has released version 4.0.2 to address this issue; please see the reference section for further details.
mailto:[email protected]
PicoZip PicoZip 4.0.1
Solution:
The vendor has released version 4.0.2 to address this issue; please see the reference section for further details.
mailto:[email protected]
PicoZip PicoZip 4.0.1
References
PicoZip Zipinfo.DLL Buffer Overflow Vulnerability
References:
References:
- PicoZip Change Log (PicoZip)
- PicoZip Web Site (PicoZip)
- Secunia Research: PicoZip 'zipinfo.dll' Multiple Archives Buffer Overflow (Secunia Research
)