Re: Winzip vulnerability

From: Torgeir Bakken (MVP) (Torgeir.Bakken-spam_at_hydro.com)
Date: 03/04/04


Date: Thu, 04 Mar 2004 02:04:32 +0100

Mike wrote:

> This vulnerability was released on Feb 27/04 by iDefense:
> http://eletters.eweek.com/zd1/cts?d=79-516-5-8-14720-
> 60837-1
>
> Does anyone know if the vulnerability applies to WinXP's
> ability to open and create ZIP compressed files?

Hi

Actually, if you read the iDefense article a bit closer, this flaw does
not affect ZIP files, but MIME-encoded files, so I would say no, it does
not apply to WinXP's ability to open and create ZIP compressed files.

And from WinZip's Web site:

WinZip 9.0 Fixes a Security Issue with MIME-Encoded Files
http://www.winzip.com/fmwz90.htm

<quote>
Q: What types of files are affected?

A: Files with the following extensions, which are by default associated
with WinZip and which are used in connection with MIME-encoded data, are
affected: .MIM, .UUE, .UU, .B64, .BHX, .HQX, and .XXE.

Other filetypes associated with WinZip, such as .ZIP, .TAR, and .CAB, are
not affected.
</quote>

--
torgeir
Microsoft MVP Scripting and WMI, Porsgrunn Norway
Administration scripting examples and an ONLINE version of the 1328 page
Scripting Guide:
http://www.microsoft.com/technet/community/scriptcenter/default.mspx


Relevant Pages

  • Re: Unzip archives from the command prompt (...or script)
    ... several hundreds of compressed files (.zip stored in a tree ... ZipGenius has a command line interface ... Last freeware version of PowerArchiver: ... -- torgeir, Microsoft MVP Scripting and WMI, Porsgrunn Norway Administration scripting examples and an ONLINE version of the 1328 page Scripting Guide: ...
    (microsoft.public.windowsxp.general)
  • Re: How would i download updates NOT through Windows Update
    ... > that are in place on the network here at my work establishment is disabling ... > the ability to update through Windows Update. ... -- torgeir, Microsoft MVP Scripting and WMI, Porsgrunn Norway Administration scripting examples and an ONLINE version of the 1328 page Scripting Guide: ...
    (microsoft.public.windowsupdate)
  • Re: How would i download updates NOT through Windows Update
    ... >> that are in place on the network here at my work establishment is ... >> the ability to update through Windows Update. ... > torgeir, Microsoft MVP Scripting and WMI, Porsgrunn Norway ...
    (microsoft.public.windowsupdate)
  • Re: Switch Users when part of AD Domain?
    ... > local users and switch between them without logging out the user that is ... > I loose this Ability when I join a AD Domain. ... Microsoft MVP Scripting and WMI, ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Removing automatic display of compressed files
    ... > I wish to remove the automtaic display of compressed files ... regsvr32 /u zipfldr.dll ... -- torgeir, Microsoft MVP Scripting and WMI, Porsgrunn Norway Administration scripting examples and an ONLINE version of the 1328 page Scripting Guide: ...
    (microsoft.public.windowsxp.customize)