CVE-2009-2261: Input Validation
PeaZIP 2.6.1, 2.5.1, and earlier on Windows allows user-assisted remote attackers to execute arbitrary commands via a .zip archive with a .txt file whose name contains | (pipe) characters and a command.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2261?
CVE-2009-2261 is considered a medium severity vulnerability due to the potential for remote command execution.
How do I fix CVE-2009-2261?
To fix CVE-2009-2261, upgrade to a version of PeaZIP later than 2.6.1 that addresses this vulnerability.
What versions of PeaZIP are affected by CVE-2009-2261?
CVE-2009-2261 affects PeaZIP versions up to and including 2.6.1 as well as earlier versions.
What is the impact of CVE-2009-2261?
The impact of CVE-2009-2261 allows attackers to execute arbitrary commands on a victim's system by exploiting specially crafted .zip archives.
Who can exploit the vulnerability in CVE-2009-2261?
CVE-2009-2261 can be exploited by user-assisted remote attackers who can trick users into opening malicious .zip files.