Multiple LHA Buffer Overflow/Directory Traversal Vulnerabilities
BID:10243
Info
Multiple LHA Buffer Overflow/Directory Traversal Vulnerabilities
| Bugtraq ID: | 10243 |
| Class: | Unknown |
| CVE: |
CVE-2004-0234 CVE-2004-0235 CVE-2005-0644 CVE-2005-0643 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 30 2004 12:00AM |
| Updated: | Jul 12 2009 04:07AM |
| Credit: | Discovery of these vulnerabilities has been credited to Ulf Harnhammar. |
| Vulnerable: |
WinZip WinZip 9.0 Stalker CGPMcAfee 3.2 SGI ProPack 3.0 SGI ProPack 2.4 RedHat Linux 7.3 i686 RedHat Linux 7.3 i386 RedHat Linux 7.3 RedHat lha-1.14i-9.i386.rpm Red Hat Fedora Core1 RARLAB WinRar 3.20 Mr. S.K. LHA 1.17 Mr. S.K. LHA 1.15 Mr. S.K. LHA 1.14 McAfee WebShield SMTP 4.5 McAfee Webshield Appliances McAfee VirusScan Professional McAfee VirusScan for NetApp McAfee VirusScan Enterprise 8.0 i McAfee VirusScan Command Line McAfee VirusScan 9.0 McAfee VirusScan 8.0 McAfee VirusScan 7.1 McAfee VirusScan 7.0 McAfee VirusScan 6.0 McAfee VirusScan 5.0 McAfee VirusScan 4.5.1 McAfee VirusScan 4.5 McAfee VirusScan 4.0.3 McAfee VirusScan 4.0 McAfee VirusScan 3.0 McAfee VirusScan 2.0 McAfee VirusScan 1.0 McAfee Virex McAfee SecurityShield for Microsoft ISA Server McAfee PortalShield for Microsoft SharePoint McAfee NetShield for Netware McAfee Managed VirusScan McAfee LinuxShield McAfee Internet Security Suite McAfee GroupShield for Mail Servers with ePO McAfee GroupShield for Lotus Domino McAfee GroupShield for Exchange 5.5 McAfee ASaP VirusScan 0 McAfee Active Virus Defense SMB Edition McAfee Active Threat Protection McAfee Active Mail Protection F-Secure Personal Express 4.7 F-Secure Personal Express 4.6 F-Secure Personal Express 4.5 F-Secure Internet Security 2004 F-Secure Internet Security 2003 F-Secure Internet Gatekeeper 6.32 F-Secure Internet Gatekeeper 6.31 F-Secure F-Secure for Firewalls 6.20 F-Secure Anti-Virus for Workstations 5.42 F-Secure Anti-Virus for Workstations 5.41 F-Secure Anti-Virus for Windows Servers 5.42 F-Secure Anti-Virus for Windows Servers 5.41 F-Secure Anti-Virus for Samba Servers 4.60 F-Secure Anti-Virus for MS Exchange 6.21 F-Secure Anti-Virus for MIMEsweeper 5.42 F-Secure Anti-Virus for MIMEsweeper 5.41 F-Secure Anti-Virus for Linux Workstations 4.52 F-Secure Anti-Virus for Linux Workstations 4.51 F-Secure Anti-Virus for Linux Servers 4.52 F-Secure Anti-Virus for Linux Servers 4.51 F-Secure Anti-Virus for Linux Gateways 4.52 F-Secure Anti-Virus for Linux Gateways 4.51 F-Secure Anti-Virus Client Security 5.52 F-Secure Anti-Virus Client Security 5.50 F-Secure Anti-Virus 2004 F-Secure Anti-Virus 2003 Clearswift MailSweeper 4.3.13 Clearswift MailSweeper 4.3.11 Clearswift MailSweeper 4.3.10 Clearswift MailSweeper 4.3.8 Clearswift MailSweeper 4.3.7 Clearswift MailSweeper 4.3.6 SP1 Clearswift MailSweeper 4.3.6 Clearswift MailSweeper 4.3.5 Clearswift MailSweeper 4.3.4 Clearswift MailSweeper 4.3.3 Clearswift MailSweeper 4.3 Clearswift MailSweeper 4.2 Clearswift MailSweeper 4.1 Clearswift MailSweeper 4.0 Barracuda Networks Barracuda Spam Firewall 3.1.18 firmware Barracuda Networks Barracuda Spam Firewall 3.1.17 firmware |
| Not Vulnerable: |
Barracuda Networks Barracuda Spam Firewall 3.3.03.022 firmware |
Discussion
Multiple LHA Buffer Overflow/Directory Traversal Vulnerabilities
LHA has been reported prone to multiple vulnerabilities that may allow a malicious archive to execute arbitrary code or corrupt arbitrary files when the archive is operated on.
The first issues reported have been assigned the CVE candidate identifier (CAN-2004-0234). LHA is reported prone to two stack-based buffer-overflow vulnerabilities. An attacker may exploit these vulnerabilities to execute supplied instructions with the privileges of the user who invoked the affected LHA utility.
The second set of issues has been assigned CVE candidate identifier (CAN-2004-0235). In addition to the buffer-overflow vulnerabilities that were reported, LHA has been reported prone to several directory-traversal issues. An attacker may likely exploit these directory-traversal vulnerabilities to corrupt/overwrite files in the context of the user who is running the affected LHA utility.
**NOTE: Reportedly, this issue may also cause a denial-of-service condition in the ClearSwift MAILsweeper products due to code dependency.
**Update: Many F-Secure Anti-Virus products are also reported prone to the buffer-overflow vulnerability.
LHA has been reported prone to multiple vulnerabilities that may allow a malicious archive to execute arbitrary code or corrupt arbitrary files when the archive is operated on.
The first issues reported have been assigned the CVE candidate identifier (CAN-2004-0234). LHA is reported prone to two stack-based buffer-overflow vulnerabilities. An attacker may exploit these vulnerabilities to execute supplied instructions with the privileges of the user who invoked the affected LHA utility.
The second set of issues has been assigned CVE candidate identifier (CAN-2004-0235). In addition to the buffer-overflow vulnerabilities that were reported, LHA has been reported prone to several directory-traversal issues. An attacker may likely exploit these directory-traversal vulnerabilities to corrupt/overwrite files in the context of the user who is running the affected LHA utility.
**NOTE: Reportedly, this issue may also cause a denial-of-service condition in the ClearSwift MAILsweeper products due to code dependency.
**Update: Many F-Secure Anti-Virus products are also reported prone to the buffer-overflow vulnerability.
Exploit / POC
Multiple LHA Buffer Overflow/Directory Traversal Vulnerabilities
The following proof-of-concept exploit has been supplied by "narko tix" <[email protected]>. This proof of concept was observed to also cause an access violation in WinZip and WinRAR products.
This vulnerability can be tested using the PIRANA exploitation framework available at the following location:
http://www.guay-leroux.com/projects/pirana-0.2.1.tar.gz
The following proof-of-concept exploit has been supplied by "narko tix" <[email protected]>. This proof of concept was observed to also cause an access violation in WinZip and WinRAR products.
This vulnerability can be tested using the PIRANA exploitation framework available at the following location:
http://www.guay-leroux.com/projects/pirana-0.2.1.tar.gz
Solution / Fix
Multiple LHA Buffer Overflow/Directory Traversal Vulnerabilities
Solution:
Please see the referenced advisories for further information.
Redhat lha-1.14i-9.i386.rpm
Mr. S.K. LHA 1.14
SGI ProPack 3.0
F-Secure Anti-Virus for Linux Servers 4.52
F-Secure Anti-Virus for Linux Gateways 4.52
F-Secure Anti-Virus for Samba Servers 4.60
F-Secure Anti-Virus for Windows Servers 5.41
F-Secure Anti-Virus for MIMEsweeper 5.41
F-Secure Anti-Virus for Workstations 5.41
F-Secure Anti-Virus for Windows Servers 5.42
F-Secure Anti-Virus for MIMEsweeper 5.42
F-Secure Anti-Virus for Workstations 5.42
F-Secure Anti-Virus Client Security 5.50
F-Secure F-Secure for Firewalls 6.20
F-Secure Anti-Virus for MS Exchange 6.21
F-Secure Internet Gatekeeper 6.32
Solution:
Please see the referenced advisories for further information.
Redhat lha-1.14i-9.i386.rpm
-
Red Hat lha-1.14i-9.1.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/lha-1.14i-9.1.i386.rpm
Mr. S.K. LHA 1.14
-
Conectiva lha-1.14i-2U80_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/lha-1.14i-2U80_1cl.i386.rpm -
Conectiva lha-1.14i-8382U90_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/lha-1.14i-8382U90_1cl.i386. rpm -
Debian lha_1.14i-2woody1_alpha.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/non-free/l/lha/lha_1.14i-2wood y1_alpha.deb -
Debian lha_1.14i-2woody1_arm.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/non-free/l/lha/lha_1.14i-2wood y1_arm.deb -
Debian lha_1.14i-2woody1_i386.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/non-free/l/lha/lha_1.14i-2wood y1_i386.deb -
Debian lha_1.14i-2woody1_ia64.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/non-free/l/lha/lha_1.14i-2wood y1_ia64.deb -
Debian lha_1.14i-2woody1_m68k.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/non-free/l/lha/lha_1.14i-2wood y1_m68k.deb -
Debian lha_1.14i-2woody1_powerpc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/non-free/l/lha/lha_1.14i-2wood y1_powerpc.deb -
Debian lha_1.14i-2woody1_s390.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/non-free/l/lha/lha_1.14i-2wood y1_s390.deb -
Debian lha_1.14i-2woody1_sparc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/non-free/l/lha/lha_1.14i-2wood y1_sparc.deb -
Fedora lha-1.14i-12.1.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/i386 /lha-1.14i-12.1.i386.rpm -
Fedora lha-1.14i-12.1.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/x86_ 64/lha-1.14i-12.1.x86_64.rpm -
RedHat lha-1.14i-4.7.3.3.legacy.i386.rpm
RedHat Linux 7.3
http://download.fedoralegacy.org/redhat/7.3/updates/i386/lha-1.14i-4.7 .3.3.legacy.i386.rpm -
RedHat lha-1.14i-9.4.legacy.i386.rpm
RedHat Linux 9
http://download.fedoralegacy.org/redhat/9/updates/i386/lha-1.14i-9.4.l egacy.i386.rpm
SGI ProPack 3.0
-
SGI patch10080.tar.gz
ftp://patches.sgi.com/support/free/security/patches/ProPack/3/patch100 80.tar.gz
F-Secure Anti-Virus for Linux Servers 4.52
-
F-Secure fsav-4.52-hotfix4.tgz
ftp://ftp.f-secure.com/support/hotfix/fsav-linux/fsav-4.52-hotfix4.tgz
F-Secure Anti-Virus for Linux Gateways 4.52
-
F-Secure fsav-4.52-hotfix4.tgz
ftp://ftp.f-secure.com/support/hotfix/fsav-linux/fsav-4.52-hotfix4.tgz
F-Secure Anti-Virus for Samba Servers 4.60
-
F-Secure fsav-4.60-hotfix1.tgz
ftp://ftp.f-secure.com/support/hotfix/fsav-samba/fsav-4.60-hotfix1.tgz
F-Secure Anti-Virus for Windows Servers 5.41
-
F-Secure fsavsr541-14-signed.fsfix
ftp://ftp.f-secure.com/support/hotfix/fsav-server/fsavsr541-14-signed. fsfix
F-Secure Anti-Virus for MIMEsweeper 5.41
-
F-Secure fsavsr541-14-signed.fsfix
ftp://ftp.f-secure.com/support/hotfix/fsav-mime/fsavsr541-14-signed.fs fix
F-Secure Anti-Virus for Workstations 5.41
-
F-Secure fsavwk552-08-signed.fsfix
ftp://ftp.f-secure.com/support/hotfix/fsav/fsavwk552-08-signed.fsfix
F-Secure Anti-Virus for Windows Servers 5.42
-
F-Secure fsavsr541-14-signed.fsfix
ftp://ftp.f-secure.com/support/hotfix/fsav-server/fsavsr541-14-signed. fsfix
F-Secure Anti-Virus for MIMEsweeper 5.42
-
F-Secure fsavsr541-14-signed.fsfix
ftp://ftp.f-secure.com/support/hotfix/fsav-mime/fsavsr541-14-signed.fs fix
F-Secure Anti-Virus for Workstations 5.42
-
F-Secure fsavwk552-08-signed.fsfix
ftp://ftp.f-secure.com/support/hotfix/fsav/fsavwk552-08-signed.fsfix
F-Secure Anti-Virus Client Security 5.50
-
F-Secure fsavwk552-08-signed.fsfix
ftp://ftp.f-secure.com/support/hotfix/fsavcs/fsavwk552-08-signed.fsfix
F-Secure F-Secure for Firewalls 6.20
-
F-Secure fsavfw620-05.fsfix
ftp://ftp.f-secure.com/support/hotfix/fsav-fw/fsavfw620-05.fsfix
F-Secure Anti-Virus for MS Exchange 6.21
-
F-Secure fscss631-03.fsfix
ftp://ftp.f-secure.com/support/hotfix/fsav-mse/fscss631-03.fsfix
F-Secure Internet Gatekeeper 6.32
-
F-Secure fscss631-03.fsfix
ftp://ftp.f-secure.com/support/hotfix/fsig/fscss631-03.fsfix
References
Multiple LHA Buffer Overflow/Directory Traversal Vulnerabilities
References:
References:
- [SECURITY] Fedora Core 1 Update: lha-1.14i-12.1 (Fedora)
- Barracuda Spam Firewall Product Page (Barracuda Networks)
- CGPMcAfee (Stalker)
- F-Secure Security Bulletin FSC-2004-1 - Buffer overflow caused by malformed LHA (F-Secure)
- LHA for UNIX Version 1.17 (LHA for UNIX)
- McAfee plugin affected by LHA buffer overflow exploit (Stalker)
- McAfee Security Bulletin - March 17th 2005 (McAfee)
- RHSA-2004:178-09 - An updated LHA package fixes security vulnerabilities (RedHat)
- RHSA-2004:219-07 - Updated tcpdump packages fix various vulnerabilities (RedHat)
- WinRAR Homepage (WinRAR)
- WinZip Homepage (WinZip)
- Re: [SECURITY] [DSA 515-1] New lha packages fix several vulnerabilities; Re: (GOTO Masanori
)