This application requires Javascript for optimal performance.

eZip.Wizard.Filename.Buffer.Overflow

Release Date

Apr 15, 2009

Severity

critical

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt against a buffer-overflow vulnerability in eZip Wizard.

The vulnerability is caused by an error when the vulnerable software handles a malicious .zip file. It allows a remote attacker to execute arbitrary code via sending a crafted .zip file.

Affected Products

ediSys eZip Wizard 3.0

Recommended Actions

Currently we are not aware of any vendor supplied patch for this issue.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2009-1028

Reference/s

http://www.securityfocus.com/bid/34044 (BugTraq)

Reference: VID-17397