|
InnerMedia DynaZip ZIP Archive Handling Multiple Buffer Overflow Vulnerabilities
DynaZip is prone to multiple remote buffer-overflow vulnerabilities when handling malicious ZIP archives. A successful attack can allow a remote attacker to corrupt process memory by triggering an overflow condition. This may lead to arbitrary code execution in the context of an affected user and facilitate a remote compromise. These vulnerabilities affect the following: DynaZip Max with DZIP32.DLL 5.0.0.7 DynaZip Max Secure with DZIPS32.DLL 6.0.0.4. Other versions may be vulnerable as well. NOTE: TurboZIP 6.0 Build 002021004 is also affected by the first issue because it uses the DynaZip library. |
|
|
Privacy Statement |