Vulnerability Development mailing list archives

Re: Securax Security Advisory: Windows98 contains a seriousbufferoverflow with long filenameextensions.


From: markus-kern () GMX NET (Markus Kern)
Date: Tue, 25 Apr 2000 10:30:22 +0200


LiGHTNiNG wrote:

The Buffer Overflow also occured, when I tried to delete the
file by pressing the "ENTF" (DEL) key.(Win98/German)

While looking into this bug I found out that if you have
installed WinZip with shell extensions the Explorer crashes
when trying to delete the file or doing a right click on
it:

EXPLORER verursachte einen Fehler durch eine ungültige Seite
in Modul WZSHLEXT.DLL bei 0137:10001109.
Register:
EAX=00000000 CS=0137 EIP=10001109 EFLGS=00010246
EBX=0047b48c SS=013f ESP=008aeef6 EBP=00000001
ECX=008a0298 DS=013f ESI=00000001 FS=3acf
EDX=00000000 ES=013f EDI=000000f0 GS=26ee
Bytes bei CS:EIP:
00 00 00 00 89 6c 24 4c c7 44 24 50 ff ff ff ff
Stapelwerte:
a1c8008a 07700047 f4200000 0005008a
4c440000 216c004c 00c07fdb b3810000
00000047 a1d80000 00000047 00010000
00010000 b1640000 00000047 00000000

This might be the problem you experienced.

-- Markus


Current thread: