PT-2006-3140 · Cam Unzip+2 · Cam Unzip+2
Tan Chew Keong
·
Published
2006-05-09
·
Updated
2018-10-18
·
CVE-2006-2161
CVSS v2.0
5.1
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
TZipBuilder version 1.79.03.01
Abakt versions 0.9.2 through 0.9.3-beta1
CAM UnZip versions 4.0 through 4.3
Description
The issue allows user-assisted attackers to execute arbitrary code via a ZIP archive that contains a file with a long file name, potentially leading to buffer overflow.
Recommendations
For TZipBuilder version 1.79.03.01, update to a version that fixes the buffer overflow issue.
For Abakt versions 0.9.2 through 0.9.3-beta1, avoid using the affected software to open ZIP archives from untrusted sources until a patch is available.
For CAM UnZip versions 4.0 through 4.3, consider disabling the ZIP archive processing feature until a fixed version is released.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Abakt
Cam Unzip
Tzipbuilder