Vulnerability in WinZip Could Compromise Security

Security analysts on Friday reported that versions of the popular ZIP file management program WinZip have a serious security flaw. According to security intelligence firm iDefense Inc., an error in the parameter parsing code in these versions “allows remote attackers to execute arbitrary code.” The attacker would have to construct a specially designed MIME archive (with one of .mim, .uue, .uu, .b64, .bhx, .hqx and .xxe extensions) and distribute the file users, the company explained.

Once opened, the attack would trick WinZip into executing code contained in the attacking file. iDefense said it had a functioning proof-of-concept attack demonstrating the problem. The malicious file could be distributed by e-mail, on a Web page, or through peer-to-peer networks. Files handled by WinZip are not normally executable, so many users are less-hesitant to launch them, even when they come from unknown sources. This problem makes those files much more inherently dangerous.

News source: eWeek

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • MisterWong
  • Fleck
  • Furl
  • Ma.gnolia
  • Reddit
  • Slashdot
  • Spurl
  • Technorati
  • YahooMyWeb
195 Views
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...
Print This Post Print This Post Email This Post Email This Post

Leave a Comment

Vulnerability in WinZip Could Compromise Security

Security analysts on Friday reported that versions of the popular ZIP file management program WinZip have a serious security flaw. According to security intelligence firm iDefense Inc., an error in the parameter parsing code in these versions “allows remote attackers to execute arbitrary code.” The attacker would have to construct a specially designed MIME archive (with one of .mim, .uue, .uu, .b64, .bhx, .hqx and .xxe extensions) and distribute the file users, the company explained.

Once opened, the attack would trick WinZip into executing code contained in the attacking file. iDefense said it had a functioning proof-of-concept attack demonstrating the problem. The malicious file could be distributed by e-mail, on a Web page, or through peer-to-peer networks. Files handled by WinZip are not normally executable, so many users are less-hesitant to launch them, even when they come from unknown sources. This problem makes those files much more inherently dangerous.

News source: eWeek

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • MisterWong
  • Fleck
  • Furl
  • Ma.gnolia
  • Reddit
  • Slashdot
  • Spurl
  • Technorati
  • YahooMyWeb
0 Views
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...
Print This Post Print This Post Email This Post Email This Post

Leave a Comment

About

A daily blog about software. Reviews, tips and software downloads for Windows, Linux, Mac, Palm, Pocket PC, and Mobile Phones. The best programs and games.

Site Search