找回密码
 注册账户
查看: 263|回复: 0

Vulnerability in WinZip (v7/v8) Could Compromise Security

[复制链接]
admin 发表于 2012-3-28 00:17:31 | 显示全部楼层 |阅读模式
Security analysts on Friday reported that versions of the popular ZIP file management program WinZip have a serious security flaw.

According to security intelligence firm iDefense Inc., an error in the parameter parsing code in these versions “allows remote attackers to execute arbitrary code.”

The attacker would have to construct a specially designed MIME archive (with one of .mim, .uue, .uu, .b64, .bhx, .hqx and .xxe extensions) and distribute the file users, the company explained.

Once opened, the attack would trick WinZip into executing code contained in the attacking file. iDefense said it had a functioning proof-of-concept attack demonstrating the problem.

The malicious file could be distributed by e-mail, on a Web page, or through peer-to-peer networks.

Files handled by WinZip are not normally executable, so many users are less-hesitant to launch them, even when they come from unknown sources. This problem makes those files much more inherently dangerous.

According to iDefense, versions 7 and 8, as well as the latest beta of WinZip 9 are vulnerable to this attack. However, the released Version 9 of WinZip is not vulnerable.

In addition to upgrading, users can prevent an attack by turning off automatic handling of these file types by WinZip in Windows Explorer. In Windows XP, choose Tools-Folder Options, select the File Types tab, scroll down to the appropriate file types, and either delete them or reassign file handling to another program.

New Source : eweek
您需要登录后才可以回帖 登录 | 注册账户

本版积分规则

存档|黑屋|手机|网络实验室 本站服务器由美国合租以及IDCLayer国际数据提供!!!

GMT+8, 2026-6-8 08:18 , Processed in 0.010889 second(s), 7 queries , Gzip On, Redis On.

Powered by Discuz! X3.5

© 2001-2025 Discuz! Team.

快速回复 返回顶部 返回列表