This application requires Javascript for optimal performance.

TugZip.File.Parsing.Buffer.Overflow

Release Date

Nov 04, 2011

Severity

critical

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt to exploit a remote Code Execution vulnerability in TUGZip.

The vulnerability is caused by an error when handling a malformed zip file. It can be exploited via a crafted zip file, leading to remote code execution.

Affected Products

TUGZip 3.00

Recommended Actions

Currently we are not aware of any patches supplied by the vendor for this issue.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2008-4779

Reference: VID-29634