PT-2006-5164 · Powerzip · Powerzip
Tan Chew Keong
·
Published
2006-08-25
·
Updated
2017-07-20
·
CVE-2006-4359
CVSS v2.0
5.1
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
PowerZip version 7.06 Build 3895
Description
A stack-based buffer overflow issue allows remote attackers to execute arbitrary code via a ZIP archive containing a long filename.
Recommendations
For PowerZip version 7.06 Build 3895, consider avoiding the use of ZIP archives with long filenames until a patch is available. As a temporary workaround, restrict the handling of ZIP files to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Powerzip