Description
ZIP Password Recovery 2.30 contains a denial of service vulnerability that allows attackers to crash the application by providing maliciously crafted input. Attackers can create a specially prepared text file with specific characters to trigger an application crash when selecting a ZIP file.
Problem types
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
Credits
ZwX
References
www.exploit-db.com/exploits/47894 (ExploitDB-47894)
www.top-password.com/purchase.html (Vendor Homepage)
www.vulncheck.com/...ord-recovery-zip-file-denial-of-service (VulnCheck Advisory: ZIP Password Recovery 2.30 - 'ZIP File' Denial of Service)