Buffer overflow in Yz1 0.30 and 0.32, as used in IZArc 4.4, ZipGenius 6.3.2.3116, and Explzh (extension) 8.14, allows attackers to execute arbitrary code via a crafted archive file, related to filename handling.
References
Link Resource
http://yz1.com Permissions Required Product
https://gist.github.com/illikainen/315a420a9c28cbe882e16b8eba40b2e1 Exploit Third Party Advisory
https://gist.github.com/illikainen/ced14e08e00747fef613ba619bb25bb4 Exploit Third Party Advisory
https://illikainen.dev/advisories/014-yz1-izarc Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-02-22T15:59:20

Updated: 2021-02-22T15:59:20

Reserved: 2020-08-13T00:00:00


Link: CVE-2020-24175

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-02-22T16:15:12.780

Modified: 2021-02-27T01:30:50.087


Link: CVE-2020-24175

JSON object: View

cve-icon Redhat Information

No data.

CWE