MidnightBSD

Advisories for picozip

CVE-2006-2909 HIGH

Stack-based buffer overflow in the info tip shell extension (zipinfo.dll) in PicoZip 4.01 allows remote attackers to execute arbitrary code via a long filename in an (1) ACE, (2) RAR, or (3) ZIP archive, which is triggered when the user moves the mouse over the archive.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
picozip picozip 4.01
CVE-2007-1673 HIGH

unzoo.c, as used in multiple products including AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-399,

Products Affected

Vendor Product Version
avast avast_antivirus 4.6.394
unzoo unzoo 4.4
avira antivir_personal 7
avast avast_antivirus_professional 4.6.665
amavis amavis *
avast avast_antivirus_home 4.6.655
barracuda_networks barracuda_spam_firewall model_200
panda panda_antivirus_and_firewall 2007
picozip picozip *
avast avast_antivirus_home 4.6.691
avast avast_antivirus_home 4.7.844
barracuda_networks barracuda_spam_firewall model_600
barracuda_networks barracuda_spam_firewall model_500
avast avast_antivirus_professional 4.6.691
avast avast_antivirus_professional 4.7.844
avast avast_antivirus_professional 4.7.1043
avast avast_antivirus_home 4.7.827
barracuda_networks barracuda_spam_firewall model_400
avast avast_antivirus_professional 4.7.1098
avast avast_antivirus_professional 4.6.603
avast avast_antivirus_home 4.7.1098
avira antivir_personal *
avast avast_antivirus_home 4.6.665
winace winace *
avast avast_antivirus_professional 4.6
avira antivir 6.35.00.00
rahul_dhesi zoo *
avast avast_antivirus_home 4.6.652
avira antivir 7.04.00.23
barracuda_networks barracuda_spam_firewall model_800
avast avast_antivirus 4.7.700
avast avast_antivirus *
avast avast_antivirus_professional 4.0
avast avast_antivirus_professional 4.7.827
avast avast_antivirus_home 4.0
avast avast_antivirus_professional 4.7.869
avast avast_antivirus_home 4.7.1043
avast avast_antivirus_professional 4.6.652
avira antivir *
barracuda_networks barracuda_spam_firewall *
avast avast_antivirus_home 4.7.869
avast avast_antivirus_home 4.6
barracuda_networks barracuda_spam_firewall model_900
avast avast_antivirus 4.7.652
panda panda_antivirus 2007
barracuda_networks barracuda_spam_firewall model_100
barracuda_networks barracuda_spam_firewall model_300
CVE-2007-2058 MEDIUM

Directory traversal vulnerability in Acubix PicoZip 4.02 allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in the file path in an (1) GZ, (2) TAR, (3) RAR, (4) JAR, or (5) ZIP archive.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
picozip picozip 4.02
CVE-2007-2536 HIGH

PicoZip allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
picozip picozip 4.01
picozip picozip 4.02