Security 10748 Published by

Unchecked Buffer in File Decompression Functions Could Lead to Code Execution (Q329048)

Zipped files (files having a .zip extension) provide a means to store information in a way that uses less space on a hard disk. This is accomplished by compressing the files that are put into in the zipped file. On Windows 98 with Plus! Pack, Windows Me and Windows XP, the Compressed Folders feature allows zipped files to be treated as folders. The Compressed Folders feature can be used to create, add files to, and extract files from zipped files.

Two vulnerabilities exist in the Compressed Folders function.

Read more