vendor:
jZip
by:
motaz reda
7,8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: jZip
Affected Version From: jZip v2.0.0.132900
Affected Version To: jZip v2.0.0.132900
Patch Exists: YES
Related CWE: N/A
CPE: a:jzip:jzip
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7
2014
seh unicode buffer overflow (DOS)
This exploit is a SEH Unicode buffer overflow vulnerability in jZip v2.0.0.132900. The vulnerability is triggered when a specially crafted zip file is opened, causing a denial of service. The exploit author created a zip file with a payload of 862 A characters, followed by two 4-byte NSEH and SEH values, and then 3198 D characters. The payload is then followed by a .txt extension.
Mitigation:
The vendor has released a patch to address this vulnerability.