vendor:
ALZip
by:
C4SS!0 G0M3S
7,5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: ALZip
Affected Version From: 8.12.0.3
Affected Version To: 8.12.0.3
Patch Exists: NO
Related CWE: N/A
CPE: a:estsoft:alzip:8.12.0.3
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: WIN-XP SP3 PORTUGUESE BRAZILIAN
2010
Exploit Buffer Overflow AlZip(SEH)
ESTsoft ALZip is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data. Attackers may leverage this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
Mitigation:
Perform adequate boundary checks on user-supplied data.