CVE-2007-2536: High severity PicoZip PicoZip vulnerability
Published May 9, 2007
·Updated
PicoZip allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.
Affected Software
2 affected components
PicoZip PicoZip=4.01
PicoZip PicoZip=4.02
Event History
May 9, 2007
CVE Published
01:19 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2536?
CVE-2007-2536 has been classified as a moderate severity vulnerability due to its potential to cause denial of service.
2
What causes the vulnerability identified by CVE-2007-2536?
The vulnerability in CVE-2007-2536 is caused by a ZOO archive's direntry structure that can point back to a previous file, creating an infinite loop.
3
How do I fix CVE-2007-2536?
To mitigate CVE-2007-2536, it is recommended to update to a fixed version of PicoZip or avoid opening untrusted ZOO archives.
4
Which versions of PicoZip are affected by CVE-2007-2536?
CVE-2007-2536 affects PicoZip versions 4.01 and 4.02.
5
Can CVE-2007-2536 be exploited remotely?
Yes, CVE-2007-2536 can be exploited remotely by attackers through specially crafted ZOO archives.