CVE-2006-6884: Buffer Overflow
Published Dec 31, 2006
·Updated
Buffer overflow in the WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 Build 6667 allows remote attackers to execute arbitrary code via a long argument to the CreateNewFolderFromName method, a different vulnerability than CVE-2006-5198.
Affected Software
1 affected component
Winzip Winzip=10.0_build_6667
Event History
Dec 31, 2006
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityWeaknessAffected Software
Jan 5, 2007
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-6884?
CVE-2006-6884 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2006-6884?
To fix CVE-2006-6884, update to the latest version of WinZip that addresses this vulnerability.
3
Who is affected by CVE-2006-6884?
CVE-2006-6884 affects users of WinZip version 10.0 Build 6667.
4
What type of attack does CVE-2006-6884 enable?
CVE-2006-6884 enables remote attackers to execute arbitrary code on the affected system.
5
What is the affected component in CVE-2006-6884?
The affected component in CVE-2006-6884 is the WZFILEVIEW.FileViewCtrl.61 ActiveX control.