Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers to execute arbitrary code via a MIME archive with certain long MIME parameters. This was fixed in WinZip 8.1 SR-2 in March of 2004. You can find more information on the subject on the following pages of the winzip site:
http://www.winzip.com/wz81sr2.htm
http://www.winzip.com/fmwz90.htm
Publication date: Tue, 23 Nov 2004 11:00:00 +0000