vendor:
ZipWrangler
by:
TecR0c & Sud0
7,8
CVSS
HIGH
SEH 0day exploit
119
CWE
Product Name: ZipWrangler
Affected Version From: 1.20
Affected Version To: 1.20
Patch Exists: YES
Related CWE: N/A
CPE: a:zipwrangler:zipwrangler:1.20
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP sp3 En (VMWARE)
2010
ZipWrangler 1.20 (.zip) SEH 0day exploit
This exploit is for ZipWrangler 1.20 (.zip) SEH 0day vulnerability. It is a buffer overflow exploit which uses a local file header, central file header, end of central directory file header and a payload of 4064 A's, 6 bytes of NSEH, 4 bytes of SEH, 20 bytes of NOPs and a shellcode of 351 bytes. The exploit is written in Perl and is used to create a malicious zip file.
Mitigation:
The vendor has released a patch for this vulnerability.