InnerMedia DynaZip ZIP Archive Handling Multiple Buffer Overflow Vulnerabilities
BID:19143
CVE-2006-3985 |Info
InnerMedia DynaZip ZIP Archive Handling Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 19143 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-3985 CVE-2008-4420 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 25 2006 12:00AM |
| Updated: | Jul 05 2016 09:38PM |
| Credit: | Discovered by Tan Chew Keong. |
| Vulnerable: |
InnerMedia DynaZip Library 6.0 .4 InnerMedia DynaZip Library 5.0 .7 HP Performance Agent 4.72 HP Performance Agent 4.70 HP Performance Agent 4.60 HP OpenView Performance Agent 4.72 HP OpenView Performance Agent 4.70 HP OpenView Performance Agent 4.6 Filestream TurboZIP 6.0 Build 002021004 ConeXware PowerArchiver 9.62.3 |
| Not Vulnerable: |
InnerMedia DynaZip Library 6.0 .5 InnerMedia DynaZip Library 5.0 .8 ConeXware PowerArchiver 9.63 |
Discussion
InnerMedia DynaZip ZIP Archive Handling Multiple Buffer Overflow Vulnerabilities
DynaZip is prone to multiple remote buffer-overflow vulnerabilities when handling malicious ZIP archives.
A successful attack can allow a remote attacker to corrupt process memory by triggering an overflow condition. This may lead to arbitrary code execution in the context of an affected user and facilitate a remote compromise.
These vulnerabilities affect the following:
DynaZip Max with DZIP32.DLL 5.0.0.7
DynaZip Max Secure with DZIPS32.DLL 6.0.0.4.
Other versions may be vulnerable as well.
NOTE: TurboZIP 6.0 Build 002021004 is also affected by the first issue because it uses the DynaZip library.
DynaZip is prone to multiple remote buffer-overflow vulnerabilities when handling malicious ZIP archives.
A successful attack can allow a remote attacker to corrupt process memory by triggering an overflow condition. This may lead to arbitrary code execution in the context of an affected user and facilitate a remote compromise.
These vulnerabilities affect the following:
DynaZip Max with DZIP32.DLL 5.0.0.7
DynaZip Max Secure with DZIPS32.DLL 6.0.0.4.
Other versions may be vulnerable as well.
NOTE: TurboZIP 6.0 Build 002021004 is also affected by the first issue because it uses the DynaZip library.
Exploit / POC
InnerMedia DynaZip ZIP Archive Handling Multiple Buffer Overflow Vulnerabilities
The researcher responsible for discovering these issues has developed proof-of-concept exploits. These exploits are not publicly available.
The researcher responsible for discovering these issues has developed proof-of-concept exploits. These exploits are not publicly available.
Solution / Fix
InnerMedia DynaZip ZIP Archive Handling Multiple Buffer Overflow Vulnerabilities
Solution:
The vendor has released DZIP32.DLL 5.0.0.8 and DZIPS32.DLL 6.0.0.5 to address these issues. Please contact the vendor for details.
ConeXware PowerArchiver 9.62.3
Solution:
The vendor has released DZIP32.DLL 5.0.0.8 and DZIPS32.DLL 6.0.0.5 to address these issues. Please contact the vendor for details.
ConeXware PowerArchiver 9.62.3
-
ConeXware PowerArchiver 9.63
http://www.powerarchiver.com/download/
References
InnerMedia DynaZip ZIP Archive Handling Multiple Buffer Overflow Vulnerabilities
References:
References:
- DynaZip DZIP32.DLL/DZIPS32.DLL Buffer Overflow Vulnerabilities (Tan Chew Keong)
- InnerMedia Home Page (InnerMedia)
- PowerArchiver DZIPS32.DLL Buffer Overflow Vulnerability (Tan Chew Keong)
- TurboZIP (FileStream)
- TurboZIP ZIP Repair Buffer Overflow Vulnerability (Tan Chew Keong)
- [vuln.sg] DynaZip DZIP32.DLL/DZIPS32.DLL Buffer Overflow Vulnerabilities ([email protected])
- [vuln.sg] TurboZIP ZIP Repair Buffer Overflow Vulnerabilit ([email protected])
- HPSBMA02396 SSRT080175 rev.1 - HP OpenView Performance Agent and HP Performance (HP)