AplusWebMaster
Topic Starter
FYI…
- http://isc.sans.org/diary.php?storyid=1861
Last Updated: 2006-11-15 19:48:38 UTC
"WinZip Computing released a new build of WinZip 10 that fixes a critical security vulnerability in this popular ZIP program. The vulnerability exists in an ActiveX component that is shipped with WinZip 10 only (so if you are running previous versions of WinZip you are not affected by this vulnerability). This ActiveX component is marked safe for scripting which means that a remote attacker can exploit it if you visit a web page hosting the exploit. Build 7245 of WinZip 10 is available at http://www.winzip.com/wz7245.htm . If you, for some reason, cannot upgrade, you should disable the affected ActiveX control (WZFILEVIEW.FileViewCtrl.61) – its CLSID is A09AE68F-B14D-43ED-B713-BA413F034904.
UPDATE:
*MS06-067 ( http://isc.sans.org/diary.php?storyid=1854 ) actually disables this vulnerability. Beside the other things that this update does, it also sets the kill bits for vulnerable ActiveX components…
UPDATE 2:
Couple of exploits for this vulnerability have been already released, so be sure to either patch WinZip or install MS06-067*…"
- http://www.winzip.com/wz7245.htm
"…Previous versions of WinZip are not affected by this vulnerability…"
EDIT/ADD:
- http://secunia.com/advisories/22891/
Last Update: 2006-11-16
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch…
Software: WinZip 10.x
Original Advisory: WinZip: http://www.winzip.com/wz7245.htm
Solution: Update to version 10.0 Build 7245…
Other References:
US-CERT VU#225217: http://www.kb.cert.org/vuls/id/225217
US-CERT VU#512804: http://www.kb.cert.org/vuls/id/512804 …"

- http://isc.sans.org/diary.php?storyid=1861
Last Updated: 2006-11-15 19:48:38 UTC
"WinZip Computing released a new build of WinZip 10 that fixes a critical security vulnerability in this popular ZIP program. The vulnerability exists in an ActiveX component that is shipped with WinZip 10 only (so if you are running previous versions of WinZip you are not affected by this vulnerability). This ActiveX component is marked safe for scripting which means that a remote attacker can exploit it if you visit a web page hosting the exploit. Build 7245 of WinZip 10 is available at http://www.winzip.com/wz7245.htm . If you, for some reason, cannot upgrade, you should disable the affected ActiveX control (WZFILEVIEW.FileViewCtrl.61) – its CLSID is A09AE68F-B14D-43ED-B713-BA413F034904.
UPDATE:
*MS06-067 ( http://isc.sans.org/diary.php?storyid=1854 ) actually disables this vulnerability. Beside the other things that this update does, it also sets the kill bits for vulnerable ActiveX components…
UPDATE 2:
Couple of exploits for this vulnerability have been already released, so be sure to either patch WinZip or install MS06-067*…"
- http://www.winzip.com/wz7245.htm
"…Previous versions of WinZip are not affected by this vulnerability…"
EDIT/ADD:
- http://secunia.com/advisories/22891/
Last Update: 2006-11-16
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch…
Software: WinZip 10.x
Original Advisory: WinZip: http://www.winzip.com/wz7245.htm
Solution: Update to version 10.0 Build 7245…
Other References:
US-CERT VU#225217: http://www.kb.cert.org/vuls/id/225217
US-CERT VU#512804: http://www.kb.cert.org/vuls/id/512804 …"