OSVDB ID: 20159

Title: ZipGenius unacev2.dll ACE Archive Filename Overflow

Info

Disclosure

Oct 21, 2005

Discovery

Oct 04, 2005

Dates

Exploit

Unknown

Solution

Unknown

Description

A remote overflow exists in ZipGenius. The library "unacev2.dll" fails to perform proper bounds checking, resulting in a stack-based buffer overflow. With a specially crafted ACE archive containing a compressed file with an overly long filename, an attacker can cause arbitrary code execution resulting in a loss of integrity.

Classification

Location: Remote/Network Access Required
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Unknown
Disclosure: OSVDB Verified

Solution

Upgrade to version 6.0.2.1050 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

M.Dev Software

ZipGenius

5.5.1.468
6.0.2.1041

References

Credit

  • Tan Chew Keong - vulnBrand New Doo Doosecunia.com - Secunia Research


Direct URL: http://osvdb.org/36218