|
Compression Plus Zoo Format Stack Overflow Vulnerability
Compression Plus is prone to a stack-based buffer-overflow vulnerability. The application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer. The issue occurs when processing ZOO files. This issue allows attackers to execute arbitrary machine code in the context of users running the affected application. Failed attempts will likely crash the application, resulting in denial-of-service conditions. Compression Plus 5 and prior versions are reported vulnerable; other versions may also be affected. Other applications that import functions from the library component of the affected application may also be vulnerable to this issue. |
|
|
Privacy Statement |