vendor:
ZipLite Compression ActiveX Control
by:
shinnai
7.5
CVSS
HIGH
Buffer Overflow
Buffer Overflow
CWE
Product Name: ZipLite Compression ActiveX Control
Affected Version From: 1.8.5.3
Affected Version To: 1.8.5.3
Patch Exists: NO
Related CWE:
CPE: dart:ziplite_compression_activex_control
Platforms Tested:
2007
Dart ZipLite Compression ActiveX Control Buffer Overflow Vulnerability
The Dart ZipLite Compression ActiveX control is prone to a buffer-overflow vulnerability because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer. Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.
Mitigation:
Apply the latest patch or update from the vendor.