OSVDB ID: 20158

Title: ZipGenius zipgenius.exe UUE/XXE/MIM Archive Filename Overflow

Info

Disclosure

Oct 21, 2005

Discovery

Oct 04, 2005

Dates

Exploit

Unknown

Solution

Unknown

Description

A remote overflow exists in ZipGenius. "zipgenius.exe" fails to perform proper bounds checking, resulting in a stack-based buffer overflow. With a specially crafted UUE/XXE/MIM archive containing an encoded file with an overly long filename, an attacker can cause arbitrary code execution resulting in a loss of integrity.

Classification

Location: Remote/Network Access Required
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Unknown
Disclosure: OSVDB Verified

Solution

Upgrade to version 6.0.2.1050 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

M.Dev Software

ZipGenius

5.5.1.468
6.0.2.1041

References

Credit

  • Tan Chew Keong - vulnBrand New Doo Doosecunia.com - Secunia Research


Direct URL: http://osvdb.org/36218