Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

InnerMedia DynaZip ZIP Archive Handling Multiple Buffer Overflow Vulnerabilities

DynaZip is prone to multiple remote buffer-overflow vulnerabilities when handling malicious ZIP archives.

A successful attack can allow a remote attacker to corrupt process memory by triggering an overflow condition. This may lead to arbitrary code execution in the context of an affected user and facilitate a remote compromise.

These vulnerabilities affect the following:

DynaZip Max with DZIP32.DLL 5.0.0.7
DynaZip Max Secure with DZIPS32.DLL 6.0.0.4.

Other versions may be vulnerable as well.

NOTE: TurboZIP 6.0 Build 002021004 is also affected by the first issue because it uses the DynaZip library.







 

Privacy Statement
Copyright 2008, SecurityFocus