InnerMedia DynaZip ZIP Archive Handling Multiple Buffer Overflow Vulnerabilities

BID:19143

CVE-2006-3985 |

Info

InnerMedia DynaZip ZIP Archive Handling Multiple Buffer Overflow Vulnerabilities

Bugtraq ID: 19143
Class: Boundary Condition Error
CVE: CVE-2006-3985
CVE-2008-4420
Remote: Yes
Local: No
Published: Jul 25 2006 12:00AM
Updated: Jul 05 2016 09:38PM
Credit: Discovered by Tan Chew Keong.
Vulnerable: InnerMedia DynaZip Library 6.0 .4
InnerMedia DynaZip Library 5.0 .7
HP Performance Agent 4.72
HP Performance Agent 4.70
HP Performance Agent 4.60
HP OpenView Performance Agent 4.72
HP OpenView Performance Agent 4.70
HP OpenView Performance Agent 4.6
Filestream TurboZIP 6.0 Build 002021004
ConeXware PowerArchiver 9.62.3
Not Vulnerable: InnerMedia DynaZip Library 6.0 .5
InnerMedia DynaZip Library 5.0 .8
ConeXware PowerArchiver 9.63

Discussion

InnerMedia DynaZip ZIP Archive Handling Multiple Buffer Overflow Vulnerabilities

DynaZip is prone to multiple remote buffer-overflow vulnerabilities when handling malicious ZIP archives.

A successful attack can allow a remote attacker to corrupt process memory by triggering an overflow condition. This may lead to arbitrary code execution in the context of an affected user and facilitate a remote compromise.

These vulnerabilities affect the following:

DynaZip Max with DZIP32.DLL 5.0.0.7
DynaZip Max Secure with DZIPS32.DLL 6.0.0.4.

Other versions may be vulnerable as well.

NOTE: TurboZIP 6.0 Build 002021004 is also affected by the first issue because it uses the DynaZip library.

Exploit / POC

InnerMedia DynaZip ZIP Archive Handling Multiple Buffer Overflow Vulnerabilities

The researcher responsible for discovering these issues has developed proof-of-concept exploits. These exploits are not publicly available.

Solution / Fix

InnerMedia DynaZip ZIP Archive Handling Multiple Buffer Overflow Vulnerabilities

Solution:
The vendor has released DZIP32.DLL 5.0.0.8 and DZIPS32.DLL 6.0.0.5 to address these issues. Please contact the vendor for details.


ConeXware PowerArchiver 9.62.3

References

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report