vendor:
ZipGenius
by:
C4SS!0 G0M3S
7.8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: ZipGenius
Affected Version From: 6.3.2.3000
Affected Version To: 6.3.2.3000
Patch Exists: YES
Related CWE: N/A
CPE: a:zipgenius:zipgenius:6.3.2.3000
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: WIN-XP SP3 Brazilian Portuguese
2011
ZipGenius v6.3.2.3000 .ZIP File Buffer Overflow Exploit
ZipGenius v6.3.2.3000 is vulnerable to a buffer overflow vulnerability when processing specially crafted .ZIP files. An attacker can exploit this vulnerability to execute arbitrary code in the context of the application. This exploit creates a malicious .ZIP file that contains a payload of 1060 bytes of shellcode followed by a return address that points to the payload. The payload is then executed when the application attempts to process the malicious .ZIP file.
Mitigation:
Upgrade to the latest version of ZipGenius.