Stack-based buffer overflow in the info tip shell extension (zipinfo.dll) in PicoZip 4.01 allows remote attackers to execute arbitrary code via a long filename in an (1) ACE, (2) RAR, or (3) ZIP archive, which is triggered when the user moves the mouse over the archive.
References
Configurations
History
21 Nov 2024, 00:12
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/20481 - Patch, Vendor Advisory | |
References | () http://secunia.com/secunia_research/2006-42/advisory/ - Patch, Vendor Advisory | |
References | () http://securityreason.com/securityalert/1104 - | |
References | () http://securitytracker.com/id?1016308 - | |
References | () http://www.osvdb.org/26447 - | |
References | () http://www.picozip.com/changelog.html - | |
References | () http://www.securityfocus.com/archive/1/437103/100/0/threaded - | |
References | () http://www.securityfocus.com/archive/1/437450/100/100/threaded - | |
References | () http://www.securityfocus.com/bid/18425 - Patch | |
References | () http://www.vupen.com/english/advisories/2006/2330 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/27096 - |
Information
Published : 2006-06-16 10:02
Updated : 2025-04-03 01:03
NVD link : CVE-2006-2909
Mitre link : CVE-2006-2909
CVE.ORG link : CVE-2006-2909
JSON object : View
Products Affected
picozip
- picozip
CWE