Stack-based buffer overflow in the info tip shell extension (zipinfo.dll) in PicoZip 4.01 allows remote attackers to execute arbitrary code via a long filename in an (1) ACE, (2) RAR, or (3) ZIP archive, which is triggered when the user moves the mouse over the archive.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| picozip | picozip | 4.01 |
unzoo.c, as used in multiple products including AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| avast | avast_antivirus | 4.6.394 |
| unzoo | unzoo | 4.4 |
| avira | antivir_personal | 7 |
| avast | avast_antivirus_professional | 4.6.665 |
| amavis | amavis | * |
| avast | avast_antivirus_home | 4.6.655 |
| barracuda_networks | barracuda_spam_firewall | model_200 |
| panda | panda_antivirus_and_firewall | 2007 |
| picozip | picozip | * |
| avast | avast_antivirus_home | 4.6.691 |
| avast | avast_antivirus_home | 4.7.844 |
| barracuda_networks | barracuda_spam_firewall | model_600 |
| barracuda_networks | barracuda_spam_firewall | model_500 |
| avast | avast_antivirus_professional | 4.6.691 |
| avast | avast_antivirus_professional | 4.7.844 |
| avast | avast_antivirus_professional | 4.7.1043 |
| avast | avast_antivirus_home | 4.7.827 |
| barracuda_networks | barracuda_spam_firewall | model_400 |
| avast | avast_antivirus_professional | 4.7.1098 |
| avast | avast_antivirus_professional | 4.6.603 |
| avast | avast_antivirus_home | 4.7.1098 |
| avira | antivir_personal | * |
| avast | avast_antivirus_home | 4.6.665 |
| winace | winace | * |
| avast | avast_antivirus_professional | 4.6 |
| avira | antivir | 6.35.00.00 |
| rahul_dhesi | zoo | * |
| avast | avast_antivirus_home | 4.6.652 |
| avira | antivir | 7.04.00.23 |
| barracuda_networks | barracuda_spam_firewall | model_800 |
| avast | avast_antivirus | 4.7.700 |
| avast | avast_antivirus | * |
| avast | avast_antivirus_professional | 4.0 |
| avast | avast_antivirus_professional | 4.7.827 |
| avast | avast_antivirus_home | 4.0 |
| avast | avast_antivirus_professional | 4.7.869 |
| avast | avast_antivirus_home | 4.7.1043 |
| avast | avast_antivirus_professional | 4.6.652 |
| avira | antivir | * |
| barracuda_networks | barracuda_spam_firewall | * |
| avast | avast_antivirus_home | 4.7.869 |
| avast | avast_antivirus_home | 4.6 |
| barracuda_networks | barracuda_spam_firewall | model_900 |
| avast | avast_antivirus | 4.7.652 |
| panda | panda_antivirus | 2007 |
| barracuda_networks | barracuda_spam_firewall | model_100 |
| barracuda_networks | barracuda_spam_firewall | model_300 |
Directory traversal vulnerability in Acubix PicoZip 4.02 allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in the file path in an (1) GZ, (2) TAR, (3) RAR, (4) JAR, or (5) ZIP archive.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| picozip | picozip | 4.02 |
PicoZip allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| picozip | picozip | 4.01 |
| picozip | picozip | 4.02 |