|
|
|
Vulnerability Note VU#383779
ZIP archives containing files with large filenames can cause buffer overflows
OverviewMultiple file decompression utilities contain buffer overflow vulnerabilities for which the impacts vary.
I. DescriptionResearchers at Rapid7, Inc. have discovered that multiple file decompression utilities are susceptible to buffer overflows as a result of large filenames embedded in crafted ZIP archive files. When affected users attempt to decompress these ZIP files, the buffer overflow may result in execution of arbitrary code.II. ImpactThe impact of this vulnerability may vary depending upon the product and its execution environment. Typically, successful exploitation of a buffer overflow will allow the attacker to execute arbitrary code with the privileges of the user running the application.III. SolutionApply a patch
The vendor section of this document lists vendors who have been notified of this issue and their responses.
Systems Affected
References
http://www.rapid7.com/advisories/R7-0004.txt
Credit
This vulnerability was reported to the CERT/CC by Rapid7, Inc.
This document was written by Jeffrey P. Lanza.
Other Information
| Date Public | 10/02/2002 |
| Date First Published | 10/02/2002 04:06:40 PM |
| Date Last Updated | 01/06/2003 |
| CERT Advisory | |
| CVE Name | CAN-2002-0370 |
| Metric | 20.25 |
| Document Revision | 22 |
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|
 |