First published: Sun Dec 31 2006(Updated: )
Buffer overflow in the WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 Build 6667 allows remote attackers to execute arbitrary code via a long argument to the CreateNewFolderFromName method, a different vulnerability than CVE-2006-5198.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WinZip WinZip | =10.0_build_6667 | |
WinZip | =10.0_build_6667 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6884 has a high severity rating due to the potential for remote code execution.
To fix CVE-2006-6884, update to the latest version of WinZip that addresses this vulnerability.
CVE-2006-6884 affects users of WinZip version 10.0 Build 6667.
CVE-2006-6884 enables remote attackers to execute arbitrary code on the affected system.
The affected component in CVE-2006-6884 is the WZFILEVIEW.FileViewCtrl.61 ActiveX control.