Vulnerabilities > CVE-2007-1614 - Stack Buffer Overflow vulnerability in ZZipLib ZZip_Open_Shared_IO
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Stack-based buffer overflow in the zzip_open_shared_io function in zzip/file.c in ZZIPlib Library before 0.13.49 allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long filename.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | Gentoo Local Security Checks |
NASL id | GENTOO_GLSA-200704-05.NASL |
description | The remote host is affected by the vulnerability described in GLSA-200704-05 (zziplib: Buffer Overflow) dmcox dmcox discovered a boundary error in the zzip_open_shared_io() function from zzip/file.c . Impact : A remote attacker could entice a user to run a zziplib function with an overly long string as an argument which would trigger the buffer overflow and may lead to the execution of arbitrary code. Workaround : There is no known workaround at this time. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 24938 |
published | 2007-04-05 |
reporter | This script is Copyright (C) 2007-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/24938 |
title | GLSA-200704-05 : zziplib: Buffer Overflow |
code |
|
References
- http://osvdb.org/33838
- http://secunia.com/advisories/24586
- http://secunia.com/advisories/24708
- http://security.gentoo.org/glsa/glsa-200704-05.xml
- http://sourceforge.net/project/shownotes.php?group_id=6389&release_id=494587
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:093
- http://www.securityfocus.com/bid/23013
- http://www.securitylab.ru/forum/read.php?FID=21&TID=40858&MID=326187
- http://www.vupen.com/english/advisories/2007/0998