|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
If you have found a vulnerability, please send to our SecurityAlert Database : secalert()securityreason()com
Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com |
|
|
Home SecurityAlert Database |
|
|
Topic : | Compression Plus and Tumblweed EMF Stack Overflow
|
SecurityAlert : 1498
CVE : CVE-2006-4554
SecurityRisk : Medium (About)
Remote Exploit : Yes
Local Exploit : No
Exploit Available : No
Credit : Michael Hale Ligh (michael ligh mnin org)
Published : 08.09.2006
Affected Software : | Compression Plus and Tumblweed EMF |
 Advisory Content : The Compression Plus library is designed to handle de/compression of
popular archiving formats such as ARC, ARK, PAK, ARJ, CAB, GZ, LBR, TAR,
TAZ, TGZ, Z, ZIP, and ZOO. The code fails to properly validate input
while processing specially crafted ZOO files, which results in a
stack-based buffer overflow. Software products that implement the
Compression Plus library are vulnerable to local or remote code
execution, depending on the nature of the calling process.
Details are available from the following URL:
http://www.mnin.org/advisories/2006_cp5_tweed.pdf
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|
|
|
|