Buffer overflow in Yz1 0.30 and 0.32, as used in IZArc 4.4, ZipGenius 6.3.2.3116, and Explzh (extension) 8.14, allows attackers to execute arbitrary code via a crafted archive file, related to filename handling.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
http://yz1.com | permissions required product |
https://gist.github.com/illikainen/315a420a9c28cbe882e16b8eba40b2e1 | third party advisory exploit |
https://gist.github.com/illikainen/ced14e08e00747fef613ba619bb25bb4 | third party advisory exploit |
https://illikainen.dev/advisories/014-yz1-izarc | third party advisory exploit |