PeaZIP.Archived.FileName.Command

NamePeaZIP.Archived.FileName.Command.Injection
Last Updated DateSep 29, 2009
Release DateSep 15, 2009
SeverityCritical
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates an attack attempt against a command injection vulnerability in PeaZIP.

The vulnerability is caused by an error when the vulnerable software handles a malicious archive file. It allows a remote attacker to inject arbitrary command via sending a crafted archive files.
Affected ProductsPeaZIP 2.6.1, 2.5.1, and earlier on Windows
Recommended ActionsUpgrade to the latest version
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2261
Reference: VID-17694