ESTsoft ALZip MIM File Processing Buffer Overflow Vulnerability
BID:48493
Info
ESTsoft ALZip MIM File Processing Buffer Overflow Vulnerability
| Bugtraq ID: | 48493 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2011-1336 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 29 2011 12:00AM |
| Updated: | Jun 29 2011 12:00AM |
| Credit: | Takahiko Funakubo |
| Vulnerable: |
ESTsoft ALZip 8.21 |
| Not Vulnerable: | |
Discussion
ESTsoft ALZip MIM File Processing Buffer Overflow Vulnerability
ESTsoft ALZip is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Attackers may leverage this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
ESTsoft ALZip versions 8.21 and prior are vulnerable.
ESTsoft ALZip is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Attackers may leverage this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
ESTsoft ALZip versions 8.21 and prior are vulnerable.
Exploit / POC
ESTsoft ALZip MIM File Processing Buffer Overflow Vulnerability
Currently, we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently, we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
ESTsoft ALZip MIM File Processing Buffer Overflow Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
ESTsoft ALZip MIM File Processing Buffer Overflow Vulnerability
References:
References:
- ALZip vulnerable to buffer overflow (JPCERT/CC and IPA)
- ALZip vulnerable to buffer overflow (IPA)
- ALZip Homepage (ESTsoft)