OSVDB ID: 19906

Title: InnerMedia DynaZip DUNZIP32.dll Filename Overflow

Info

Disclosure

Oct 27, 2004

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Oct 27, 2004

Description

A remote overflow exists in InnerMedia's DynaZip as used in multiple products. The 'DUNZIP32.DLL' library fails to perform proper bounds checking resulting in a buffer overflow. With a specially crafted '.zip' file containing a file with an overly long filename, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Unknown
Disclosure: OSVDB Verified

Solution

Contact your vendor for an appropriate upgrade. An upgrade is required as there are no known workarounds.

Products

CheckMark Software Inc.

Payroll

3.9.6
3.9.5
3.9.4
3.9.3
3.9.2
3.9.1
3.7.5

MultiLedger

7.0.1
7.0.0
6.0.5
6.0.3

RealNetworks, Inc.

RealPlayer

10
10.5 (6.0.12.1053)
10.5 (6.0.12.1040)

RealPlayer Beta

10.5 (6.0.12.1016)

RealOne Player

v2
v1

Inner Media, Inc.

DynaZip

5.00.03

dtSearch Corporation

dtSearch Desktop with Spider

7.10 (Build 7045)

McAfee, Inc.

VirusScan

10 Build 10.0.21

References

Credit

  • Juha-Matti Laurio - juha-matti.laurionetti.fi -
  • Yuji Ukai - alerteEye.com - eEye Digital Security


Direct URL: http://osvdb.org/36218