eZip.Wizard.Filename.Buffer.Overflow

Release DateApr 15, 2009
SeverityCritical
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates an attack attempt against a buffer-overflow vulnerability in eZip Wizard.

The vulnerability is caused by an error when the vulnerable software handles a malicious .zip file. It allows a remote attacker to execute arbitrary code via sending a crafted .zip file.
Affected ProductsediSys eZip Wizard 3.0
Recommended ActionsCurrently we are not aware of any vendor supplied patch for this issue.
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1028
Reference/shttp://www.securityfocus.com/bid/34044 (BugTraq)
Reference: VID-17397