vendor:
ZippHo
by:
mr_me
7.5
CVSS
HIGH
Buffer Overflow
121
CWE
Product Name: ZippHo
Affected Version From: 3.0.6
Affected Version To: 3.0.6
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP sp3
ZippHo 3.0.6 (.zip) 0day stack buffer overflow PoC exploit
This is a proof-of-concept exploit for a stack buffer overflow vulnerability in ZippHo 3.0.6. The exploit takes advantage of a flaw in the handling of .zip files, allowing an attacker to overflow a buffer and potentially execute arbitrary code.
Mitigation:
The vendor should release a patch to fix the buffer overflow vulnerability. In the meantime, users are advised to avoid opening or downloading untrusted .zip files.