Family: Gain a shell remotely --> Category: infos
PicoZip ZipInfo.dll Buffer Overflow Vulnerability Vulnerability Scan
Vulnerability Scan Summary
Checks version of PicoZip
Detailed Explanation for this Vulnerability Test
The remote Windows host contains an application that is affected by a
The remote host is running PicoZip, a file compression utility for
According to the registry, the version of PicoZip installed on the
remote Windows host fails to properly check the size of filenames
before copying them into a finite-sized buffer within the
'zipinfo.dll' info tip shell extension. Using a specially-crafted
ACE, RAR, or ZIP file, a possible hacker may be able to exploit this issue
to execute arbitrary code on the affected host subject to the
rights of the user running the affected application.
See also :
Upgrade to PicoZip version 4.02 or later.
High / CVSS Base Score : 7.0
Click HERE for more information and discussions on this network vulnerability scan.