Windows XP Unchecked Buffer in File Decompression Functions Vulnerability Patch

Software Screenshot:
Windows XP Unchecked Buffer in File Decompression Functions Vulnerability Patch
Software Details:
Version: MS02-054
Upload Date: 2 Nov 15
Developer: Microsoft
Distribution Type: Freeware
Downloads: 64
Size: 372 Kb

Rating: 3.5/5 (Total Votes: 2)

This patch addresses two vulnerabilities. An unchecked buffer exists in the program that handles the decompressing of files from a zipped file. When this program tries to open a file that has a specially malformed file name that is contained in a zipped file, Windows Explorer may fail, or an attacker may be able to run any code. This behavior creates a security vulnerability.

The second vulnerability is that the decompression function may put a file in a folder that is different from, or that is a child of, the target folder that is specified by the user as the location where the decompressed ZIP files are put. This behavior may allow an attacker to put a file in a known location on the user's computer; for example, an attacker may put a program in a Startup folder.

Requirements:

Windows XP

Supported Operation Systems

Other Software of Developer Microsoft

Comments to Windows XP Unchecked Buffer in File Decompression Functions Vulnerability Patch

Comments not found
Add Comment
Turn on images!