PT-2006-3140 · Cam Unzip+2 · Cam Unzip+2

Tan Chew Keong

·

Published

2006-05-09

·

Updated

2018-10-18

·

CVE-2006-2161

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions TZipBuilder version 1.79.03.01 Abakt versions 0.9.2 through 0.9.3-beta1 CAM UnZip versions 4.0 through 4.3
Description The issue allows user-assisted attackers to execute arbitrary code via a ZIP archive that contains a file with a long file name, potentially leading to buffer overflow.
Recommendations For TZipBuilder version 1.79.03.01, update to a version that fixes the buffer overflow issue. For Abakt versions 0.9.2 through 0.9.3-beta1, avoid using the affected software to open ZIP archives from untrusted sources until a patch is available. For CAM UnZip versions 4.0 through 4.3, consider disabling the ZIP archive processing feature until a fixed version is released.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-2161

Affected Products

Abakt
Cam Unzip
Tzipbuilder