PT-2010-3267 · Zipgenius · Zipgenius
Rick2600
·
Published
2010-04-29
·
Updated
2017-08-17
·
CVE-2010-1597
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ZipGenius version 6.3.1.2552
Description
The issue is a stack-based buffer overflow in the zgtips.dll component, which allows remote attackers to execute arbitrary code. This can be achieved by creating a ZIP file with an entry that has a long filename, and then tricking a user into opening this file.
Recommendations
For ZipGenius version 6.3.1.2552, consider avoiding the use of ZIP files from untrusted sources until a patch is available. As a temporary workaround, restrict the handling of ZIP files with long filenames to minimize the risk of exploitation.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zipgenius