PT-2019-12957 · Estsoft · Alzip

Published

2019-08-13

·

Updated

2020-10-06

·

CVE-2019-12807

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Alzip versions 10.83 and earlier
Description The issue is caused by improper bounds checking during the parsing of crafted ISO archive file format, leading to a stack-based buffer overflow. This could allow an attacker to execute arbitrary code by persuading a victim to open a specially-crafted ISO archive file.
Recommendations For versions 10.83 and earlier, update to a version later than 10.83 to resolve the issue. As a temporary workaround, consider avoiding the use of crafted ISO archive files until a patch is available. Restrict access to untrusted ISO archive files to minimize the risk of exploitation.

Fix

Memory Corruption

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-12807

Affected Products

Alzip