PT-2021-11021 · Izarc+3 · Izarc+3

Hans Jerry Illikainenadvisoriesblogexploits

·

Published

2021-02-22

·

Updated

2021-02-27

·

CVE-2020-24175

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Yz1 versions 0.30 through 0.32 IZArc version 4.4 ZipGenius version 6.3.2.3116 Explzh (extension) version 8.14
Description: A buffer overflow issue allows attackers to execute arbitrary code via a crafted archive file, related to filename handling. This issue affects various software products that utilize the vulnerable Yz1 component.
Recommendations: For Yz1 versions 0.30 through 0.32, update to a version that fixes the buffer overflow issue. For IZArc version 4.4, consider disabling the use of Yz1 until a patch is available. For ZipGenius version 6.3.2.3116, restrict the handling of archive files to minimize the risk of exploitation. For Explzh (extension) version 8.14, avoid using the extension with potentially crafted archive files until the issue is resolved.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-24175

Affected Products

Explzh
Izarc
Yz1
Zipgenius