Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2004-1094
StatusCandidate
DescriptionBuffer overflow in InnerMedia DynaZip DUNZIP32.dll file version 5.00.03 and earlier allows remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename, as demonstrated using (1) a .rjs (skin) file in RealPlayer 10 through RealPlayer 10.5 (6.0.12.1053), RealOne Player 1 and 2, (2) the Restore Backup function in CheckMark Software Payroll 2004/2005 3.9.6 and earlier, (3) CheckMark MultiLedger before 7.0.2, (4) dtSearch 6.x and 7.x, (5) mcupdmgr.exe and mghtml.exe in McAfee VirusScan 10 Build 10.0.21 and earlier, (6) IBM Lotus Notes before 6.5.5, and other products.  NOTE: it is unclear whether this is the same vulnerability as CVE-2004-0575, although the data manipulations are the same.
PhaseAssigned (30.11.2004)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2004-1094
ReferencesBID : 11555
 BUGTRAQ : 20041027 EEYE: RealPlayer Zipped Skin File Buffer Overflow
 BUGTRAQ : 20041027 High Risk Vulnerability in RealPlayer
 BUGTRAQ : 20051223 dtSearch DUNZIP32.dll Buffer Overflow Vulnerability
 BUGTRAQ : 20060330 McAfee VirusScan DUNZIP32.dll Buffer Overflow Vulnerability
 BUGTRAQ : 20060906 IBM Lotus Notes DUNZIP32.dll Buffer Overflow Vulnerability
 CERT-VN : VU#582498
 CONFIRM : http://service.real.com/help/faq/security/041026_p...
 FRSIRT : ADV-2005-2057
 FRSIRT : ADV-2006-1176
 MISC : http://www.networksecurity.fi/advisories/dtsearch....
 MISC : http://www.networksecurity.fi/advisories/lotus-not...
 MISC : http://www.networksecurity.fi/advisories/mcafee-vi...
 MISC : http://www.networksecurity.fi/advisories/multiledg...
 MISC : http://www.networksecurity.fi/advisories/payroll.html
 MISC : http://www.securiteam.com/windowsntfocus/6Z00W00EA...
 OSVDB : 19906
 SECTRACK : 1011944
 SECTRACK : 1012297
 SECTRACK : 1016817
 SECUNIA : 17096
 SECUNIA : 17394
 SECUNIA : 18194
 SECUNIA : 19451
 XF : payroll-dunzip32-bo(22737)
 XF : realplayer-dunzip32-bo(17879)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server