PT-2018-16791 · Estsoft · Alzip
Published
2018-12-21
·
Updated
2020-08-24
·
CVE-2018-5196
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Alzip versions 10.76.0.0 and earlier
Description
The issue is caused by improper bounds checking, leading to a stack overflow. This can be exploited by persuading a victim to open a specially-crafted LZH archive file, potentially allowing an attacker to execute arbitrary code.
Recommendations
For versions 10.76.0.0 and earlier, update to a version that includes proper bounds checking to prevent the stack overflow and arbitrary code execution.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alzip