ZipCentral ZIP File Handling Buffer Overflow

high Nessus Plugin ID 21620

Synopsis

The remote Windows host has an application that is suffers from a buffer overflow vulnerability.

Description

According to its version, the ZipCentral program installed on the remote host is affected by a stack-based buffer overflow when handling a ZIP file with specially crafted filenames.

Solution

Unknown at this time.

See Also

https://secuniaresearch.flexerasoftware.com/secunia_research/2006-35/advisory/

Plugin Details

Severity: High

ID: 21620

File Name: zipcentral_overflow.nasl

Version: 1.18

Type: local

Agent: windows

Family: Windows

Published: 5/31/2006

Updated: 11/15/2018

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 7.6

Temporal Score: 6

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Information

Required KB Items: SMB/Registry/Enumerated

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 5/30/2006

Reference Information

CVE: CVE-2006-2439

BID: 18160

CWE: 119