Monday, September 06, 2004

Vulnerabilities found in WinZip

Vulnerabilities found in WinZip: "An attacker could potentially exploit unspecified buffer overflow vulnerabilities in WinZip to execute arbitrary code or gain access to systems, SecurityTracker said in an advisory.
The Silver Spring, Md.-based vulnerability watchdog said the flaws affect 9.0 and prior versions of WinZip, a file-compressing utility for Windows. The advisory said they could be exploited to execute arbitrary code and gain user access via a local system or network.
'When you're able to execute arbitrary code, you can do anything,' said Michael Haisley, a handler for the Bethesda, Md.-based Internet Storm Center, a service of the SANS Institute. 'In the past, zip files were considered safe. That has proven not to be the case.' "

No comments: