CVE-2003-1376: Medium severity winzip winzip vulnerability
Published Dec 31, 2003
·Updated
WinZip 8.0 uses weak random number generation for password protected ZIP files, which allows local users to brute force the encryption keys and extract the data from the zip file by guessing the state of the stream coder.
Affected Software
1 affected component
Winzip Winzip=8.0
Event History
Dec 31, 2003
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityWeaknessAffected Software
Oct 19, 2007
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-1376?
CVE-2003-1376 is considered a moderate severity vulnerability as it allows local users to brute force encryption keys.
2
How do I fix CVE-2003-1376?
To fix CVE-2003-1376, upgrade to a version of WinZip that uses strong random number generation for password protection.
3
What software versions are affected by CVE-2003-1376?
CVE-2003-1376 specifically affects WinZip version 8.0.
4
What type of attack does CVE-2003-1376 allow?
CVE-2003-1376 allows local users to perform brute force attacks on password protected ZIP files.
5
Is CVE-2003-1376 relevant for modern systems?
While CVE-2003-1376 is an older vulnerability, it remains relevant for systems still using WinZip 8.0.