Vulnerabilities Found In WinZip

Vulnerabilities Found In WinZip
SecurityTracker reports about some vulnerabilities found in WinZip.





An attacker may potentially gain control of a victim's PC via local system or a network using such techniques as buffer overflow. Malicious user may trigger an attack through a carefully crafted command line causing overflow. The flaw affects version 9.0 and earlier of a popular file-compressing utility for Windows.

Mansfield, Conn.-based WinZip Computing Inc. reported that the problem was discovered during an internal investigation of the WinZip source code and a fix (9.0 SR-1) has already been created.

You can download it from http://www.winzip.com/wz90sr1.htm.

See also:





Permalink: Vulnerabilities Found In WinZip