Home→Descriptions→SA12430
| Secunia ID | |
| Release Date |
02 Sep 2004 |
| Last Change |
08 Jan 2007 |
| Criticality | |
| Solution Status |
Vendor Patch |
| Software |
WinZip 3.x |
| Where | |
| Impact |
System accessThis covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user. |
| Description |
Multiple vulnerabilities has been reported in Winzip, which potentially can be exploited to compromise a user's system. 1) Some unspecified vulnerabilities, which can be exploited to cause buffer overflows. Successful exploitation can potentially lead to execution of arbitrary code. 2) A problem caused due to insufficient validation of command-line arguments. This can be exploited by using a specially crafted argument to cause a buffer overflow and potentially execute arbitrary code. |
| Solution |
Update to 9.0 SR-1: |
| Reported by |
Reported by vendor. |