Obsahuje:
  • všechny e-ziny od 9/1999
  • celou databázi NEWS
  • soutěže 2000-2011
  • další články a BONUSY

Security - News

http://crypto-world.info

Crypto - News | Security - News

09 / 2004
Vybrali pro vás: TR - Tomáš Rosa, JP - Jaroslav Pinkava, PV - Pavel Vondruška, VK - Vlastimil Klíma

WinZip - p?ete?ení umož?uje spušt?ní libovolného kódu, hotfix

02.09.2004
Version(s): 9.0 and prior versions Description: Some vulnerabilities were reported in WinZip. A remote or local user may be able to execute arbitrary code. The vendor reported that they discovered some vulnerabilities, including potential buffer overflows, during an internal review of the WinZip code. In addition, a WinZip user discovered a buffer overflow, where a local user can supply a specially crafted WinZip command line to trigger the overflow. No further details were provided. Impact: A remote or local user may be able to cause arbitrary code to be executed. Solution: A fix (9.0 SR-1) is available at: http://www.winzip.com/upgrade.htm Vendor URL: www.winzip.com/wz90sr1.htm (Links to External Site)
Zdroj: http://www.securitytracker.com/alerts/2004/Sep/1011132.html
Autor: VK


Design: Webdesign