Chilkat Zip ChilkatZip2.DLL Multiple Arbitrary File Overwrite Vulnerabilities
BID:24806
Info
Chilkat Zip ChilkatZip2.DLL Multiple Arbitrary File Overwrite Vulnerabilities
| Bugtraq ID: | 24806 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3633 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 07 2007 12:00AM |
| Updated: | Apr 25 2012 08:10PM |
| Credit: | shinnai is credited with the discovery of this vulnerability. |
| Vulnerable: |
IBM Rational Policy Tester 8.5 IBM Rational AppScan Reporting Console 8.0.1.1 IBM Rational AppScan Reporting Console 8.0.1 IBM Rational AppScan Reporting Console 5.5.0.2 IBM Rational AppScan Reporting Console 5.2 IBM Rational AppScan Enterprise 8.0.1.1 IBM Rational AppScan Enterprise 8.0.1 IBM Rational AppScan Enterprise 8.0.0.1 IBM Rational AppScan Enterprise 8.0.0 IBM Rational AppScan Enterprise 5.5.0.2 IBM Rational AppScan Enterprise 5.5 Fix Pack 1 IBM Rational AppScan Enterprise 5.5 IBM Rational AppScan Enterprise 5.2 Chilkat Zip 12.4.2.0 |
| Not Vulnerable: |
IBM Rational Policy Tester 8.5.0.1 IBM Rational AppScan Reporting Console 8.5.0.1 IBM Rational AppScan Enterprise 8.5.0.1 |
Discussion
Chilkat Zip ChilkatZip2.DLL Multiple Arbitrary File Overwrite Vulnerabilities
Chilkat Zip ActiveX control is prone to multiple vulnerabilities that let attackers overwrite arbitrary files on the victim's computer in the context of the vulnerable application using the ActiveX control (typically Internet Explorer).
These issues affect Chilkat Zip 12.4.2.0; other versions may also be affected.
Chilkat Zip ActiveX control is prone to multiple vulnerabilities that let attackers overwrite arbitrary files on the victim's computer in the context of the vulnerable application using the ActiveX control (typically Internet Explorer).
These issues affect Chilkat Zip 12.4.2.0; other versions may also be affected.
Exploit / POC
Chilkat Zip ChilkatZip2.DLL Multiple Arbitrary File Overwrite Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting user to view a maliciously crafted web page.
The following exploit is available:
To exploit these issues, an attacker must entice an unsuspecting user to view a maliciously crafted web page.
The following exploit is available:
Solution / Fix
Chilkat Zip ChilkatZip2.DLL Multiple Arbitrary File Overwrite Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Chilkat Zip ChilkatZip2.DLL Multiple Arbitrary File Overwrite Vulnerabilities
References:
References: