Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Microsoft Compressed Folders Hostile Decompression Path Vulnerability

The Compressed Folders feature allows zipped archives to be treated as folders. The vulnerability is the result of a flaw in the decompression routine. This results in an attacker being able to specify a hostile path for files when a zipped archive is decompressed.

This will allow an attacker to decompress files and store the files in an attacker-specified directory on the filesystem.







 

Privacy Statement
Copyright 2008, SecurityFocus