PT-2018-16791 · Estsoft · Alzip

Published

2018-12-21

·

Updated

2020-08-24

·

CVE-2018-5196

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Alzip versions 10.76.0.0 and earlier
Description The issue is caused by improper bounds checking, leading to a stack overflow. This can be exploited by persuading a victim to open a specially-crafted LZH archive file, potentially allowing an attacker to execute arbitrary code.
Recommendations For versions 10.76.0.0 and earlier, update to a version that includes proper bounds checking to prevent the stack overflow and arbitrary code execution.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-5196

Affected Products

Alzip