Microchip Data Systems ZipTV TZipTV ARJ File Handling Buffer Overflow Vulnerability
BID:19884
CVE-2006-2482 |Info
Microchip Data Systems ZipTV TZipTV ARJ File Handling Buffer Overflow Vulnerability
| Bugtraq ID: | 19884 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-2482 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 07 2006 12:00AM |
| Updated: | Sep 07 2006 10:28PM |
| Credit: | Discovered by Tan Chew Keong. |
| Vulnerable: |
Microchip Data Systems ZipTV for Delphi 7 2006.1.26 Microchip Data Systems ZipTV for C++ Builder 2006.1.16 |
| Not Vulnerable: | |
Discussion
Microchip Data Systems ZipTV TZipTV ARJ File Handling Buffer Overflow Vulnerability
The TZipTV component of ZipTV is prone to a buffer-overflow vulnerability when handling malformed ARJ archives. Successful exploitation may allow an attacker to crash the application crash or execute arbitrary code.
ZipTV for Delphi 7 version 2006.1.26 and ZipTV for C++ Builder version 2006-1.16 are known to be vulnerable; other versions may also be affected.
The TZipTV component of ZipTV is prone to a buffer-overflow vulnerability when handling malformed ARJ archives. Successful exploitation may allow an attacker to crash the application crash or execute arbitrary code.
ZipTV for Delphi 7 version 2006.1.26 and ZipTV for C++ Builder version 2006-1.16 are known to be vulnerable; other versions may also be affected.
Exploit / POC
Microchip Data Systems ZipTV TZipTV ARJ File Handling Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Microchip Data Systems ZipTV TZipTV ARJ File Handling Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
Microchip Data Systems ZipTV TZipTV ARJ File Handling Buffer Overflow Vulnerability
References:
References:
- ZipTV ARJ Archive Handling and unacev2.dll Buffer Overflows (Secunia)
- ZipTV Home Page (Microchip Data Systems)