CVE-2020-24175

Buffer overflow in Yz1 0.30 and 0.32, as used in IZArc 4.4, ZipGenius 6.3.2.3116, and Explzh (extension) 8.14, allows attackers to execute arbitrary code via a crafted archive file, related to filename handling.
References
Link Resource
http://yz1.com Permissions Required Product
https://gist.github.com/illikainen/315a420a9c28cbe882e16b8eba40b2e1 Exploit Third Party Advisory
https://gist.github.com/illikainen/ced14e08e00747fef613ba619bb25bb4 Exploit Third Party Advisory
https://illikainen.dev/advisories/014-yz1-izarc Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:yz1:yz1:0.30:*:*:*:*:*:*:*
cpe:2.3:a:yz1:yz1:0.32:*:*:*:*:*:*:*

History

No history.

Information

Published : 2021-02-22 16:15

Updated : 2024-02-28 18:08


NVD link : CVE-2020-24175

Mitre link : CVE-2020-24175

CVE.ORG link : CVE-2020-24175


JSON object : View

Products Affected

yz1

  • yz1
CWE
CWE-787

Out-of-bounds Write