First published: Wed Dec 31 2003(Updated: )
WinZip 8.0 uses weak random number generation for password protected ZIP files, which allows local users to brute force the encryption keys and extract the data from the zip file by guessing the state of the stream coder.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Corel WinZip | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1376 is considered a moderate severity vulnerability as it allows local users to brute force encryption keys.
To fix CVE-2003-1376, upgrade to a version of WinZip that uses strong random number generation for password protection.
CVE-2003-1376 specifically affects WinZip version 8.0.
CVE-2003-1376 allows local users to perform brute force attacks on password protected ZIP files.
While CVE-2003-1376 is an older vulnerability, it remains relevant for systems still using WinZip 8.0.