vendor:
Quickzip
by:
moigai
7,8
CVSS
HIGH
Denial of Service
20
CWE
Product Name: Quickzip
Affected Version From: 5.1.8.1
Affected Version To: 5.1.8.1
Patch Exists: YES
Related CWE: N/A
CPE: a:quickzip:quickzip:5.1.8.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3 En (VM)
2010
Quickzip 5.1.8.1 Denial of Service Vulnerability
A denial of service vulnerability exists in Quickzip 5.1.8.1, which allows an attacker to crash the program by creating a specially crafted zip file with a filename length shorter than the length specified in the central directory header. In the case of length specified equals 0x7, the program crash when the actual length is smaller than 0x4.
Mitigation:
Upgrade to the latest version of Quickzip.