[NT] WinHKI unacev2.dll Buffer Overflow



The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html

- - - - - - - - -



WinHKI unacev2.dll Buffer Overflow
------------------------------------------------------------------------


SUMMARY

Secunia Research has discovered a vulnerability in WinHKI, which can be
exploited by malicious people to compromise a user's system.

The vulnerability is caused due to a boundary error in ztvunacev2.dll
(UNACEV2.DLL) when extracting an ACE archive containing a file with an
overly long filename. This can be exploited to cause a stack-based buffer
overflow when a user extracts a specially crafted ACE archive.

DETAILS

Vulnerable Systems:
* WinHKI version 1.66
* WinHKI version 1.67

Immune Systems:
* WinHKI version 1.68

Solution:
Update to version 1.68 available from:
<http://www.winhki.com/en/download.htm>
http://www.winhki.com/en/download.htm

Time Table:
30/03/2006 - Initial vendor notification.
01/04/2006 - Initial vendor reply.
01/05/2006 - Public disclosure.


ADDITIONAL INFORMATION

The information has been provided by Tan Chew Keong, Secunia Research.
The original article can be found at:
<http://secunia.com/secunia_research/2006-25/advisory/>
http://secunia.com/secunia_research/2006-25/advisory/



========================================


This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@xxxxxxxxxxxxxx
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@xxxxxxxxxxxxxx


====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.



Relevant Pages

  • [NT] Multiple Vulnerabilities in WinAce and WinHKI File Archievers
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Multiple vulnerabilities in WinAce and WinHKI allow a remote attacker to ... This is a normal LHA compressed file header: ... To recreate this vulnerability we need to do shorten the length of the ...
    (Securiteam)
  • [NT] WinHKI Directory traversal
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... WinHKI Directory traversal ... A directory traversal vulnerability in WinHKI allows attackers to ... In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. ...
    (Securiteam)
  • [NT] Borland Products idsql32.dll Buffer Overflow Vulnerability
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Borland Products idsql32.dll Buffer Overflow Vulnerability ... processing SQL statements using the "DbiQExec" function. ... In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. ...
    (Securiteam)
  • [UNIX] phpBB Modified By Przemo Arbitary Code Execution
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... A directory traversal vulnerability and insecure file inclusion ... script that contains arbitrary code. ... In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. ...
    (Securiteam)
  • [EXPL] phpStat Authentication Bypass Vulnerability (Exploit, Setup.PHP)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... phpStat is vulnerable to an authentication bypass vulnerability, ... In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. ...
    (Securiteam)