Overview
A buffer overflow vulnerability in the WinZip program could allow a remote attacker to execute arbitrary code on a vulnerable system.
Description
WinZip Computing, Inc.'s WinZip is a popular utility for creating and extracting a variety of archive file formats on Microsoft Windows-based systems. A buffer overflow error exists in the way that WinZip handles certain parameters of MIME archives. This error results in a vulnerability when WinZip attempts to interpret invalid data in a MIME-encoded file. |
Impact
An attacker could execute arbitrary code of their choice on a vulnerable system. |
Solution
Upgrade to the latest version of the software |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Thanks to iDefense Security Advisory for reporting this vulnerability.
This document was written by Chad R Dougherty based on information provided by iDefense and WinZip
Other Information
CVE IDs: | None |
Severity Metric: | 7.70 |
Date Public: | 2004-02-27 |
Date First Published: | 2004-03-01 |
Date Last Updated: | 2004-03-01 15:50 UTC |
Document Revision: | 13 |