Click to See Complete Forum and Search --> : WinZip Service release


emr
November 8th, 2002, 01:18 PM
WinZip 8.1 SR-1 is out if anyone is interested.

Just d/loaded it, haven't had a chance to check for any new features.

emr

Whoops, a link would be handy. Find it here (http://www.winzip.com/upgrade.htm) .

MacGyver
November 8th, 2002, 02:12 PM
WinZip 8.1 Service Release 1 (SR-1) includes a change to the original release of WinZip 8.1 . The change addresses a vulnerability that is already properly handled, as of WinZip 8.0, for Zip files; WinZip 8.1 SR-1 addresses it for the other archive types supported by WinZip, such as TAR and CAB.
WinZip will now warn you if you attempt to open any archive that uses a parent folder (that is, "..") specification for any of the files that it contains. The reason for the warning is that extraction from such an archive could allow files to be extracted to locations outside of the folder tree that you have specified for the extraction. A malicious individual who created such an archive and convinced you to extract its contents could exploit this to overwrite important files elsewhere on your system.

NooNoo
November 8th, 2002, 02:21 PM
Thanks!

emr
November 9th, 2002, 07:50 AM
Cheers Mac, didn't have a chance last night to read up about it.

emr