|
ZipTV ARJ Archive Handling and unacev2.dll Buffer Overflows
|
|
Secunia Advisory:
|
SA20270
|
|
|
Release Date:
|
2006-09-07
|
|
Popularity:
|
7,594 views
|
|
|
Critical:
|
 Moderately critical
|
|
Impact:
|
System access
|
|
Where:
|
From remote
|
|
Solution Status:
|
Unpatched
|
|
| Software: | ZipTV Compression Components
|
|
|
Secunia CVSS-2 Score:
|
Available in Secunia business solutions
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| Advisory Content (Page 1 of 3) | [ 1 ] [ 2 ] [ 3 ] | |
|
Description: Secunia Research has discovered two vulnerabilities in ZipTV, which can be exploited by malicious people to compromise an application using the library.
1) A boundary error within the TZipTV component when listing files in ARJ archives can be exploited to cause a heap-based buffer overflow via a specially-crafted ARJ archive with an overly large ARJ header block.
Successful exploitation allows execution of arbitrary code when a malicious ARJ archive is listed.
2) A boundary error in UNACEV2.DLL (ztvunacev2.dll) when extracting ACE archives containing a file with an overly long filename can be exploited to cause a stack-based buffer overflow.
Successful exploitation allows execution of arbitrary code when a malicious ACE archive is extracted.
The vulnerabilities have been confirmed in the following versions.
* ZipTV for Delphi 7 version 2006.1.26.
* ZipTV for C++ Builder version 2006-1.16.
Other versions may also be affected.
Change Page: [ 1 ] [ 2 ] [ 3 ]
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|