PT-2007-2996 · Zziplib · Zziplib Library

Dmcox

·

Publicado

2007-03-23

·

Atualizado

2011-03-08

·

CVE-2007-1614

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ZZIPlib Library versions prior to 0.13.49
Description The issue is a stack-based buffer overflow in the zzip open shared io function, located in zzip/file.c. This allows user-assisted remote attackers to potentially cause a denial of service, resulting in an application crash, or execute arbitrary code via a long filename.
Recommendations For versions prior to 0.13.49, update to version 0.13.49 or later to resolve the issue. As a temporary workaround, consider restricting the use of long filenames to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-1614
DTSA-56-1

Produtos afetados

Zziplib Library