header-logo
Suggest Exploit
vendor:
PowerZip
by:
fl0 fl0w
5.5
CVSS
MEDIUM
Stack buffer overflow
121
CWE
Product Name: PowerZip
Affected Version From: 7.21 (Build 4010)
Affected Version To: 7.21 (Build 4010)
Patch Exists: NO
Related CWE:
CPE:
Metasploit:
Other Scripts:
Platforms Tested: Windows 7, Windows Vista, Windows XP, Windows 2000, Windows Me, Windows 98, Windows NT 4.0

PowerZip Buffer Overflow

This is a proof-of-concept code for a buffer overflow vulnerability in PowerZip. The vulnerability allows an attacker to overwrite the stack buffer, but the code does not provide an exploit to take advantage of this. The affected versions are 7.21 (Build 4010) of PowerZip. The vulnerability is local, meaning it can be exploited by a user with local access to the vulnerable system. The vulnerability is a boundary condition error that leads to a stack buffer overflow. However, the code does not provide an exploit to actually exploit the vulnerability. The vulnerability affects Windows 7, Windows Vista, Windows XP, Windows 2000, Windows Me, Windows 98, and Windows NT 4.0. There is no known fix for this vulnerability.

Mitigation:

To avoid any problems under Windows, it is recommended to use the cygwin console.
Source

Exploit-DB raw data: