WinZip new vulnerability

For everything that's not in any way related to PureBasic. General chat etc...
User avatar
einander
Enthusiast
Enthusiast
Posts: 744
Joined: Thu Jun 26, 2003 2:09 am
Location: Spain (Galicia)

WinZip new vulnerability

Post by einander »

A vulnerability in Winzip allows arbitrary code execution just by opening a ZIP file.

http://www.winzip.com/fmwz90.htm

This issue affects all earlier versions of WinZip since WinZip 6.2, including WinZip 8.1 and WinZip 9.0 beta.

The first version of WinZip in which the problem is corrected is WinZip 9.0, released in February, 2004.
Dare2
Moderator
Moderator
Posts: 3321
Joined: Sat Dec 27, 2003 3:55 am
Location: Great Southern Land

Post by Dare2 »

Thanks for the heads-up.
Dreglor
Enthusiast
Enthusiast
Posts: 759
Joined: Sat Aug 02, 2003 11:22 pm
Location: OR, USA

Post by Dreglor »

i kind it find it funny that practicly every program has this "buffer-overflow" problem :|
don't get a new version of winzip get, toss windows and get linux!
~Dreglor
Dare2
Moderator
Moderator
Posts: 3321
Joined: Sat Dec 27, 2003 3:55 am
Location: Great Southern Land

Post by Dare2 »

Yep, I have never had that problem with linux.
  . . .
mainly because I have never managed to get it to run. :)
freedimension
Enthusiast
Enthusiast
Posts: 613
Joined: Tue May 06, 2003 2:50 pm
Location: Germany
Contact:

Post by freedimension »

Dreglor wrote:i kind it find it funny that practicly every program has this "buffer-overflow" problem :|
don't get a new version of winzip get, toss windows and get linux!
And Linux doesn't have this kind of Problems? Oh, come on. After all it is programmed in C/C++ too.
The good thing about Linux is: it isn't that widespread than Windows and therefore, if a hacker wants to get famous, he attacks Windows.
Karbon
PureBasic Expert
PureBasic Expert
Posts: 2010
Joined: Mon Jun 02, 2003 1:42 am
Location: Ashland, KY
Contact:

Post by Karbon »

You only need to go read some Linux security websites to see that these kinds of exploits are all over for Linux too.
-Mitchell
Check out kBilling for all your billing software needs!
http://www.k-billing.com
Code Signing / Authenticode Certificates (Get rid of those Unknown Publisher warnings!)
http://codesigning.ksoftware.net
Dreglor
Enthusiast
Enthusiast
Posts: 759
Joined: Sat Aug 02, 2003 11:22 pm
Location: OR, USA

Post by Dreglor »

i didn't say they did it just you don't see big problems come from them becasue most hackers are trying to get into windows system becasue there widely used and there so easy after you get something in there :\

at least linux has some protection after some one gets in
~Dreglor
freedimension
Enthusiast
Enthusiast
Posts: 613
Joined: Tue May 06, 2003 2:50 pm
Location: Germany
Contact:

Post by freedimension »

Dreglor wrote:at least linux has some protection after some one gets in
Windows has this too, at least the NT variants. The problem here is, most people go online as administrator.
The bad thing with M$ Software is the default setting.
Two Examples:
- Standard user after installation has admin rights
- Outlook Express opens Mails without user interaction, just to show it in the Preview Window
User avatar
blueznl
PureBasic Expert
PureBasic Expert
Posts: 6172
Joined: Sat May 17, 2003 11:31 am
Contact:

Post by blueznl »

never used winzip, am i safe now? :-)

(nah, using total commander for *anything* except brushing my teeth, which i don't do much anyway)

:roll:

:mrgreen:
( PB6.00 LTS Win11 x64 Asrock AB350 Pro4 Ryzen 5 3600 32GB GTX1060 6GB - upgrade incoming...)
( The path to enlightenment and the PureBasic Survival Guide right here... )
El_Choni
TailBite Expert
TailBite Expert
Posts: 1007
Joined: Fri Apr 25, 2003 6:09 pm
Location: Spain

Post by El_Choni »

LOL! Who needs teeth? You can have food injected nowadays! LOL
El_Choni
gnozal
PureBasic Expert
PureBasic Expert
Posts: 4229
Joined: Sat Apr 26, 2003 8:27 am
Location: Strasbourg / France
Contact:

Post by gnozal »

I never understood why this obsolete ZIP format is still used, and why people are paying for such a thing as WinZip 8O
There are many freeware archivers wich can handle ZIP files and many other much more powerfull formats, shareware (WinRAR...) or freeware (7-Zip...)
Dare2
Moderator
Moderator
Posts: 3321
Joined: Sat Dec 27, 2003 3:55 am
Location: Great Southern Land

Post by Dare2 »

7Zip is good!
freedimension
Enthusiast
Enthusiast
Posts: 613
Joined: Tue May 06, 2003 2:50 pm
Location: Germany
Contact:

Post by freedimension »

Or WinAce. I had a photoshop file that compressed with WinAce took 700k, with Zip 1.4Meg 8O
User avatar
blueznl
PureBasic Expert
PureBasic Expert
Posts: 6172
Joined: Sat May 17, 2003 11:31 am
Contact:

Post by blueznl »

ace rar arj zip xxx all with total commander :-)

and it's even a file manager! :-)
( PB6.00 LTS Win11 x64 Asrock AB350 Pro4 Ryzen 5 3600 32GB GTX1060 6GB - upgrade incoming...)
( The path to enlightenment and the PureBasic Survival Guide right here... )
gnozal
PureBasic Expert
PureBasic Expert
Posts: 4229
Joined: Sat Apr 26, 2003 8:27 am
Location: Strasbourg / France
Contact:

Post by gnozal »

blueznl wrote:ace rar arj zip xxx all with total commander :-)
Yes, and with the MultiArc plugin you can handle _any_ type of archive, including Installshield cabs :D
Post Reply