PT-2006-2285 · Zoo · Zoo

Josh Bressers

·

Published

2006-03-19

·

Updated

2017-07-20

·

CVE-2006-1269

CVSS v2.0

6.2

Medium

VectorAV:L/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions zoo version 2.10
Description A buffer overflow issue exists in the parse function, potentially allowing local users to execute arbitrary code via long filename command line arguments during archive creation. The impact is limited due to the local nature of the issue and the lack of setuid, but there may be scenarios where the zoo user automatically lists attacker-controlled filenames, increasing the risk.
Recommendations For zoo version 2.10, consider restricting the length of filename command line arguments to prevent buffer overflow exploitation until a patch is available. As a temporary workaround, avoid using long filenames when creating archives with zoo.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1269

Affected Products

Zoo