Windows Shell ZIP File Decompression DUNZIP32.DLL Buffer Overflow
13 Oct. 2004
Summary
eEye Digital Security has discovered a buffer overflow in DUNZIP32.DLL, a module that offers support for ZIP compressed folders in the Windows shell. An exploitable buffer overflow occurs when a user opens a ZIP folder that contains a long file name.
This buffer overflow is triggered by an integer overflow. When a ZIP file containing a long file name (greater than around 0x8000 bytes) is opened in the Windows shell as a ZIP compressed folder, a stack-based buffer overflow occurs, allowing an exception handler to be overwritten and EIP to be hijacked.