PT-2019-12957 · Estsoft · Alzip

Publicado

2019-08-13

·

Atualizado

2020-10-06

·

CVE-2019-12807

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Alzip versions 10.83 and earlier
Description The issue is caused by improper bounds checking during the parsing of crafted ISO archive file format, leading to a stack-based buffer overflow. This could allow an attacker to execute arbitrary code by persuading a victim to open a specially-crafted ISO archive file.
Recommendations For versions 10.83 and earlier, update to a version later than 10.83 to resolve the issue. As a temporary workaround, consider avoiding the use of crafted ISO archive files until a patch is available. Restrict access to untrusted ISO archive files to minimize the risk of exploitation.

Correção

Memory Corruption

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-12807

Produtos afetados

Alzip