Compression Plus Zoo Format Stack Overflow Vulnerability
BID:19796
CVE-2006-4554 |Info
Compression Plus Zoo Format Stack Overflow Vulnerability
| Bugtraq ID: | 19796 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 31 2006 12:00AM |
| Updated: | Sep 05 2006 07:38PM |
| Credit: | Michael Ligh, Greg Sinclair and Amanda Wright are credited with the discovery of this vulnerability. |
| Vulnerable: |
VCOM PowerDesk Pro 6 Tumbleweed MailGate Email Firewall 0 Canyon-Tech Power File Gold 0 Canyon-Tech Power File 0 Canyon-Tech Drag and Zip 0 BeCubed Software Compression Plus 5 |
| Not Vulnerable: |
BeCubed Software Compression Plus 5 sp 14 |
Discussion
Compression Plus Zoo Format Stack Overflow Vulnerability
Compression Plus is prone to a stack-based buffer-overflow vulnerability. The application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer. The issue occurs when processing ZOO files.
This issue allows attackers to execute arbitrary machine code in the context of users running the affected application. Failed attempts will likely crash the application, resulting in denial-of-service conditions.
Compression Plus 5 and prior versions are reported vulnerable; other versions may also be affected. Other applications that import functions from the library component of the affected application may also be vulnerable to this issue.
Compression Plus is prone to a stack-based buffer-overflow vulnerability. The application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer. The issue occurs when processing ZOO files.
This issue allows attackers to execute arbitrary machine code in the context of users running the affected application. Failed attempts will likely crash the application, resulting in denial-of-service conditions.
Compression Plus 5 and prior versions are reported vulnerable; other versions may also be affected. Other applications that import functions from the library component of the affected application may also be vulnerable to this issue.
Exploit / POC
Compression Plus Zoo Format Stack Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Compression Plus Zoo Format Stack Overflow Vulnerability
Solution:
The vendor has released service pack version 14 to address this issue. Please see the reference section for more information.
mailto:[email protected]
Solution:
The vendor has released service pack version 14 to address this issue. Please see the reference section for more information.
mailto:[email protected]
References
Compression Plus Zoo Format Stack Overflow Vulnerability
References:
References:
- Canyon Software Homepage (Canyon Software )
- Compression Plus Homepage (BeCubed Software)
- Tumbleweed Homepage (Tumbleweed )
- VCOM Homepage (VCOM)