CVE-2020-24175

Buffer overflow in Yz1 0.30 and 0.32, as used in IZArc 4.4, ZipGenius 6.3.2.3116, and Explzh (extension) 8.14, allows attackers to execute arbitrary code via a crafted archive file, related to filename handling.
References
Link Resource
https://gist.github.com/illikainen/ced14e08e00747fef613ba619bb25bb4 Exploit Third Party Advisory
https://gist.github.com/illikainen/315a420a9c28cbe882e16b8eba40b2e1 Exploit Third Party Advisory
https://illikainen.dev/advisories/014-yz1-izarc Exploit Third Party Advisory
http://yz1.com Permissions Required Product
Configurations

Configuration 1

cpe:2.3:a:yz1:yz1:0.32:*:*:*:*:*:*:*
cpe:2.3:a:yz1:yz1:0.30:*:*:*:*:*:*:*

Information

Published : 2021-02-22 04:15

Updated : 2021-02-27 01:30


NVD link : CVE-2020-24175

Mitre link : CVE-2020-24175

Products Affected
No products.
CWE