CVE-2019-12807

HIGH

ALZip <= 10.83 - Stack-based Buffer Overflow via Crafted ISO Archive Parsing

Title source: llm
STIX 2.1

Description

Alzip 10.83 and earlier version contains a stack-based buffer overflow vulnerability, caused by improper bounds checking during the parsing of crafted ISO archive file format. By persuading a victim to open a specially-crafted ISO archive file, an attacker could execution arbitrary code.

References (2)

Core 2
Core References
Product, Vendor Advisory x_refsource_misc
https://www.altools.co.kr/Download/ALZip.aspx#n

Scores

CVSS v3 7.8
EPSS 0.0162
EPSS Percentile 73.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-119 CWE-787
Status published
Products (1)
estsoft/alzip < 10.83
Published Aug 13, 2019
Tracked Since Feb 18, 2026