Files ≈ Packet Storm Packet Storm - Information Security News, Files, Tools, Exploits, Advisories and Whitepapers http://packetstormsecurity.org/ en-us Mon, 28 May 2012 04:46:27 GMT Packet Storm 144400 http://packetstormsecurity.org/ http://www.google-analytics.com/__utm.gif?utmwv=1.3&utmn=2126331715&utmcs=ISO-8859-1&utmsr=31337x31337&utmsc=32-bit&utmul=en-us&utmje=0&utmfl=-&utmcn=1&utmdt=Files%u2248%20Packet%20Storm&utmhn=packetstormsecurity.org&utmr=-&utmp=%2F1005-advisories%2Fsecunia-ziproxy.txt%2F&utmac=UA-18885198-1&utmcc=__utma%3D32867617.2126331715.1338180387.1338180387.1338180387.1%3B%2B__utmz%3D32867617.1338180387.1.1.utmccn%3D(direct)%7Cutmcsr%3D(direct)%7Cutmcmd%3D(none) Ziproxy Two Integer Overflow Vulnerabilities http://packetstormsecurity.org/files/89897/secunia-ziproxy.txt http://packetstormsecurity.org/files/89897/secunia-ziproxy.txt http://packetstormsecurity.org/files/89897/Ziproxy-Two-Integer-Overflow-Vulnerabilities.html Tue, 25 May 2010 05:25:56 GMT Secunia Research has discovered two vulnerabilities in Ziproxy, which can be exploited by malicious people to compromise a vulnerable system. An integer overflow within the "jpg2bitmap()" function in src/image.c can be exploited to cause a heap-based buffer overflow via specially crafted JPG images. An integer overflow within the "png2bitmap()" function in src/image.c can be exploited to cause a heap-based buffer overflow via specially crafted PNG images. Ziproxy version 3.0.0 is affected.