
No chance to exploit the unexploited hole now…
Published: 7 September 2004 08:45 GMT
WinZip Computing warned last month of a security flaw in WinZip, its compression/decompression tool that runs on the Windows platform. Security firm Secunia has just rated the flaw as "highly critical", the fourth highest out of its five severity levels.
WinZip versions 3.x, 6.x, 7.x, 8.x and 9.x contain vulnerabilities that could allow a remote attacker to execute malicious code. The problem is caused by a flaw in the way WinZip handles command-line inputs, and can be exploited by a malicious hacker to cause a buffer overflow.
WinZip Computing has released a patch, WinZip 9.0 Service Release 1, which it claims will resolve the buffer overflow issue.
Other changes in the patch include the addition of warning messages in some situations. For example, if a user double-clicks on an .EXE file compressed within a Zip file, WinZip will warn that the compressed file could potentially contain a virus.
The company recommends on its website that all users upgrade to version 9.0 to get the fix. Users are able to download an evaluation version of the patch but after 21 days will need to pay the $29 licence fee for WinZip, unless they are registered users in which case the upgrade is free.
The company said it was not aware of the vulnerability having been exploited in the wild when it released the patch.
This news comes only a couple of weeks after warnings that a flaw in Winamp, a media application run on Windows, has been exploited by to infect people's computers with spyware. When Secunia released the initial advisory no patch was available and it advised that users switch to another product.
The flaw has now been patched and the latest Secunia advisory, updated on Monday, advises users upgrade to Winamp 5.05.
Ingrid Marson writes for ZDNet UK.
s responsibilitieswill include: Updating database patch when applicable for production Running upgrades for the environments database Providing ...
Upgrade provisioning Security patch management Application and Server Role delivery Configuration Management Advanced inventory and management ...
GRAN,WRAN Proficiency in MSC,MSC-S ,MGW Interface & parameters Proficiency in Ericsson MSC/MSC-S/MGw functions, structure and architecture ...
Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business
Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business