Vulnerabilities Found In WinZip
SecurityTracker reports about some vulnerabilities found in WinZip.
An attacker may potentially gain control of a victim's PC via local system or a network using such techniques as buffer overflow. Malicious user may trigger an attack through a carefully crafted command line causing overflow. The flaw affects version 9.0 and earlier of a popular file-compressing utility for Windows.
Mansfield, Conn.-based WinZip Computing Inc. reported that the problem was discovered during an internal investigation of the WinZip source code and a fix (9.0 SR-1) has already been created.
You can download it from http://www.winzip.com/wz90sr1.htm.
See also:
- Juniper Networks IDP Systems Protect against New Critical Microsoft Windows Vulnerabilities
- Critical Mozilla, Thunderbird Vulnerabilities
- BindView RAZOR Team Issues New RapidFire Updates
Permalink: Vulnerabilities Found In WinZip
Posted 09/04/04 | Filed under: Security |

