First published: Wed May 09 2007(Updated: )
WinAce allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WinAce | =2.5 | |
WinAce | =2.6.0.5 | |
WinAce | =2.60 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2535 has been classified as a denial of service vulnerability.
To fix CVE-2007-2535, upgrade to a patched version of WinAce that addresses this vulnerability.
CVE-2007-2535 affects WinAce versions 2.5, 2.6.0.5, and 2.60.
CVE-2007-2535 is a vulnerability that allows remote attackers to cause an infinite loop leading to denial of service.
Currently, the primary workaround for CVE-2007-2535 is to avoid opening ZOO archives from untrusted sources.