Free Newsletters

   All InfoWorld Newsletters
Security Adviser | Roger A. Grimes » A new, unpatched Winzip10.0 vulnerability

November 20, 2006 | Comments: (0)

A new, unpatched Winzip10.0 vulnerability

New buffer overflow in Winzip 10.0

New Winzip buffer overflow exploit announced on www.milw0rm.com in the form of proof of concept code.

Works on Winzip 10.0 (7245) and below. 7245 is the latest version. Winzip has not yet released a patch. Unknown if exploit can be leveraged to remote complete control.

Posted by Roger Grimes on November 20, 2006 05:04 AM


RATE THIS ARTICLE:





 

  •  
  • COMMENTS




There is simply no excuse for buffer overflows any more. The law should be changed to permit user/victims to recover damages from the software vendor for losses due to buffer overflows. Other vulnerabilities are tricky and hard to pin down legally, but overflows are easy, and it's time to make software houses pay for selling dangerous junk.

Posted by: prowness at November 20, 2006 07:05 AM

You might just get your wish, with the new Congress.

I think they could make legislation for the egregious cases; set a high bar by basing it on "gross negligence".

As for the argument that there are already mechanisms in place to recover for damages: only if DA(s) take the trouble to organize the numerous parties that are likely to be injured by such actions into class action suits. It could use to be more streamlined; otherwise, you get the "Pinto" decision-making process, where software manufacturers _sometimes_ willfully write bad code if it will turn a quick profit...

Posted by: Steve at November 26, 2006 09:03 PM

Technology White Papers

 

InfoWorld Technology Marketplace

  • Need simple, low cost server virtualization? - Do more with less. Support fewer servers. Simplify disaster recovery. Implement proven, easy-to-use server virtualization...
  • Virtually Limitless Virtual Storage - Do you need virtualization space savings of 50% or more with virtually no performance impact? You might be able to get storage...
  • Invisible IT? - The goal of IT is to become an invisible entity within a larger organization. Eliminating visibility and road blocks IT ...
  • It Really Is Easy to be Green - "Green IT" is a popular concept. And IT organizations are learning the influence that IT purchase decisions have on data...
  • Key Strategies For SOA Testing - SOA requires a unique approach to testing. Unless you're willing to reorient your testing procedures and technology now,...
  • Eliminate Botnet Security Risks - Botnets are widely regarded as the top threat to network security. This Whitepaper explains how botnets have traditionally...

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
» BUY A LINK NOW

Sponsored Technology Links