vendor:
Brazip
by:
ITSecTeam
9,3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Brazip
Affected Version From: 9.0
Affected Version To: 9.0
Patch Exists: YES
Related CWE: N/A
CPE: a:brazip:brazip:9.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP1/SP3 EN
2009
Brazip 9.0 (.zip File) BoF Poc (SEH)
A buffer overflow vulnerability exists in Brazip 9.0 when handling .zip files. An attacker can exploit this vulnerability to execute arbitrary code in the context of the application. This vulnerability is due to a lack of proper validation of user-supplied input when handling .zip files. An attacker can exploit this vulnerability by enticing a user to open a specially crafted .zip file. Successful exploitation could result in arbitrary code execution in the context of the application.
Mitigation:
Upgrade to the latest version of Brazip 9.0