F-Secure Code execution vulnerability in ZIP and RAR archive handling

2019.05.05
Risk: Medium
Local: Yes
Remote: No
CVE: N/A
CWE: N/A

Specially crafted ZIP archives may be used to execute code on affected systems. Both RAR- and ZIP-archives can in addition be crafted to avoid successful scanning and obfuscate malicious code in the archive. It is possible to create specially crafted ZIP archives that cause a buffer overflow. This allows an attacker to execute code of his choice on affected systems. It is in addition possible to create malformed RAR- and ZIP-archives that cannot be scanned properly. This can lead to a false negative scan result.

References:

https://www.f-secure.com/en/web/labs_global/fsc-2006-1


Vote for this issue:
100%
0%

Comment it here.

Copyright 2025, cxsecurity.com

 

Back to Top