Unchecked Buffer in WinZip32 8.0

A buffer overrun condition exists in the WinZip32 8.0 compression utility that could let a user execute code arbitrarily within the security context of WinZip32.

Ken Pfeil

March 1, 2001

1 Min Read
ITPro Today logo in a gray background | ITPro Today

ReportedMarch 2, 2001, by Defcom Labs.

VERSIONS AFFECTED

  • WinZip32 8.0 for Windows 2000

  • WinZip32 8.0 for Windows NT

DESCRIPTION

A buffer overrun condition exists in the WinZip328.0 compression utility that could let a user execute code arbitrarily withinthe security context of WinZip32. This condition exists when someone uses theutility's zip-and-email feature in Windows Explorer with an extremely long filename.

VENDOR RESPONSE

Currently, no workaround or fix exists other thannot using the program's zip-and-email feature. The vendor, WinZipComputing, Inc., has acknowledged this vulnerability and will correct it inthe next release.

CREDIT
Discoveredby Peter Gründl.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like