This application requires Javascript for optimal performance.

PeaZIP.Archived.FileName.Command.Injection

Release Date

Sep 15, 2009

Severity

critical

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt against a command injection vulnerability in PeaZIP.

The vulnerability is caused by an error when the vulnerable software handles a malicious archive file. It allows a remote attacker to inject arbitrary command via sending a crafted archive files.

Affected Products

PeaZIP 2.6.1, 2.5.1, and earlier on Windows

Recommended Actions

Upgrade to the latest version

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2009-2261

Reference: VID-17694