Page 1 of 2 12 LastLast
Results 1 to 10 of 14

Thread: WinZip security flaws

  1. #1
    Senior Member
    Join Date
    May 2004
    Posts
    519

    WinZip security flaws

    For those of us that use WinZip (probably a lot of us)

    http://www.eweek.com/article2/0,1759,1642408,00.asp

    WinZip Computing Inc. recently revealed that Version 9.0 of its popular WinZip file compression program is vulnerable to a variety of security attacks. The company has released a "Service Release 1" to address the security problems.
    The WinZip advisory states that "a number of general internal improvements have been made to the WinZip program to enhance security and reliability." According to the company, the vulnerabilities were found in the course of an internal review and there is no report that any of the problems have been exploited.
    Just goes to show that everything can be exploited...


  2. #2
    Senior Member
    Join Date
    Oct 2002
    Posts
    4,055
    Yeah, I use WinZip and lately I've been pretty shocked at the number of exploits and vulnerabilities in it. I mean, for a zipping utility you would think it wouldn't have too many exploits. *sighs*
    Space For Rent.. =]

  3. #3
    Senior Member
    Join Date
    Jan 2004
    Location
    Hawaii
    Posts
    350
    WinZip? Pfft. I suggest you kiddies move on to big-boy stuff. May I suggest www.7-zip.org? It makes ZIP files better than WinZip does! Also, it has an incredible 7z compression. It decompresses like 13 formats or so. And compresses in 3 or 4, along with all the little tweaks you can do with the dictionary size and memory usage type of stuff.

    A_T
    Geek isn't just a four-letter word; it's a six-figure income.

  4. #4
    Senior Member
    Join Date
    May 2004
    Posts
    519
    I was posting it as it is the most popular of compression software .. therefor it will affect the most people.. It was for information purposes, I was not stating what compressions software people should or should not use, nor was I asking what is the best software...

  5. #5
    The Doctor Und3ertak3r's Avatar
    Join Date
    Apr 2002
    Posts
    2,744
    dambed.. I am sure I have seen this before..

    I am certain that a post on this site mentioned a flaw in Winzip that had been there since about version 6 ,, that allowed code to execute on openinig a zip archive.... code sites have been bragging for ages... but it was only with an update of V9 that fixed the problem.. that the winzip ppl finaly admitted that there was a problem..

    uh can't find it .. sure it was on AO.. well must been somewhere else.. it is months old the item..

    Cheers

    BTW: What programm doesn't have a hole or 500 waiting to be exploited..?.
    "Consumer technology now exceeds the average persons ability to comprehend how to use it..give up hope of them being able to understand how it works." - Me http://www.cybercrypt.co.nr

  6. #6
    Junior Member
    Join Date
    Jan 2005
    Posts
    8
    I've been using 7 zip because WinZip has failed to many times. Could be security related, I don't know. I do know that after making a pretty simple zip of some pics to email my agent; Winzip wouldn't open the zip it had just made. (i'm very anal and tend to test and re-test everything I do)
    Several of the other archives I had were also corupted.
    If the power is on . . . it\'s vunerable . .

  7. #7
    What happened to good 'ol winrar fans? Handles everything from tgz to zip, rar to cab, and another 25 different formats. With a free version and a MUCH higher compression ratio than winzip, I can't believe people are still sticking with winzip.

  8. #8
    AO Senior Cow-beller
    Moderator
    zencoder's Avatar
    Join Date
    Dec 2004
    Location
    Mountain standard tribe.
    Posts
    1,177
    Originally posted here by a morning chill
    What happened to good 'ol winrar fans? Handles everything from tgz to zip, rar to cab, and another 25 different formats. With a free version and a MUCH higher compression ratio than winzip, I can't believe people are still sticking with winzip.
    HERE HERE! Damn them all! A full return to COMPRESS and TAR, I say! Who needs a GUI?!?

    // Mods: sorry, blatant fun-filled troll comment.
    "Data is not necessarily information. Information does not necessarily lead to knowledge. And knowledge is not always sufficient to discover truth and breed wisdom." --Spaf
    Anyone who is capable of getting themselves made president should on no account be allowed to do the job. --Douglas Adams (1952-2001)
    "...people find it far easier to forgive others for being wrong than being right." - Albus Percival Wulfric Brian Dumbledore

  9. #9
    Junior Member
    Join Date
    Jan 2005
    Posts
    8
    but that just wouldn't be pretty enough. graphics are the other half of my world. without them I might have to get a real job and actually talk to people. in person!
    If the power is on . . . it\'s vunerable . .

  10. #10
    Senior Member
    Join Date
    Jan 2005
    Posts
    217

    Everything can or may be exploited!

    Yeah right! I agree that everything can be exploited, better be ready at all times! So, there is no such thing as maximum security after all?!?
    \"Life without FREEDOM is no life at all\". - William Wallace
    MyhomE MyboX StealtH (loop n. see loop.)
    http://www.geocities.com/sebeneleben/SOTBMulti.gif

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •