PT-2010-3267 · Zipgenius · Zipgenius

Rick2600

·

Published

2010-04-29

·

Updated

2017-08-17

·

CVE-2010-1597

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ZipGenius version 6.3.1.2552
Description The issue is a stack-based buffer overflow in the zgtips.dll component, which allows remote attackers to execute arbitrary code. This can be achieved by creating a ZIP file with an entry that has a long filename, and then tricking a user into opening this file.
Recommendations For ZipGenius version 6.3.1.2552, consider avoiding the use of ZIP files from untrusted sources until a patch is available. As a temporary workaround, restrict the handling of ZIP files with long filenames to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-1597

Affected Products

Zipgenius