|
|
| |
| eEye Digital Security has discovered a buffer overflow in DUNZIP32.DLL, a module that offers support for ZIP compressed folders in the Windows shell. An exploitable buffer overflow occurs when a user opens a ZIP folder that contains a long file name. |
| |
Credit:
The information has been provided by Derek Soeder.
The original article can be found at: http://www.eeye.com/html/research/advisories/AD20041012A.html
|
| |
This buffer overflow is triggered by an integer overflow. When a ZIP file containing a long file name (greater than around 0x8000 bytes) is opened in the Windows shell as a ZIP compressed folder, a stack-based buffer overflow occurs, allowing an exception handler to be overwritten and EIP to be hijacked.
Vendor Status:
Microsoft has released a patch for this vulnerability. The patch is available at: http://www.microsoft.com/technet/security/bulletin/MS04-034.mspx
|
|
|
|
|