vendor:
Vallen Zipper
by:
C4SS!0 G0M3S
7.8
CVSS
HIGH
Heap Overflow
119
CWE
Product Name: Vallen Zipper
Affected Version From: 2.3
Affected Version To: 2.3
Patch Exists: YES
Related CWE: N/A
CPE: 2.3
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: WIN-XP SP3 Brazil Portuguese
2011
Vallen Zipper V2.30 .ZIP File Heap Overflow
Vallen Zipper V2.30 is vulnerable to a heap overflow vulnerability when processing specially crafted .ZIP files. An attacker can exploit this vulnerability by crafting a malicious .ZIP file and sending it to the victim, which can lead to arbitrary code execution.
Mitigation:
Update to the latest version of Vallen Zipper V2.30 or use an alternative software.