ARJ Software UNARJ Remote Directory Traversal Vulnerability
BID:11436
Info
ARJ Software UNARJ Remote Directory Traversal Vulnerability
| Bugtraq ID: | 11436 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-1027 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 16 2004 12:00AM |
| Updated: | Jul 12 2009 05:56PM |
| Credit: | Disclosure of this issue is credited to Doubles. |
| Vulnerable: |
Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 2.1 Redhat Advanced Workstation for the Itanium Processor 2.1 Gentoo Linux Avaya CVLAN ARJ Software Inc. UNARJ 2.65 ARJ Software Inc. UNARJ 2.64 ARJ Software Inc. UNARJ 2.63 a ARJ Software Inc. UNARJ 2.62 ARJ Software Inc. UNARJ 2.43 |
| Not Vulnerable: | |
Discussion
ARJ Software UNARJ Remote Directory Traversal Vulnerability
Reportedly ARJ Software UNARJ is affected by a remote directory traversal vulnerability. This issue is due to a failure of the application to properly sanitize or validate file names prior to compression or decompression.
This issue may allow an attacker to arbitrarily overwrite files with a user's privileges when a malicious compressed file is decompressed with the affected application.
Reportedly ARJ Software UNARJ is affected by a remote directory traversal vulnerability. This issue is due to a failure of the application to properly sanitize or validate file names prior to compression or decompression.
This issue may allow an attacker to arbitrarily overwrite files with a user's privileges when a malicious compressed file is decompressed with the affected application.
Exploit / POC
ARJ Software UNARJ Remote Directory Traversal Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
ARJ Software UNARJ Remote Directory Traversal Vulnerability
Solution:
RedHat Fedora Linux has released advisory FEDORA-2004-414 along with fixes dealing with this and another issue. Please see the referenced advisory for more information.
Gentoo Linux has released advisory GLSA 200411-29 to address this issue. Users of affected packages are urged to execute the following commands with superuser privileges:
emerge --sync
emerge --ask --oneshot --verbose ">=app-arch/unarj-2.63a-r2"
Please see the referenced advisory for further information.
Red Hat has released an advisory (RHSA-2005:007-05) to address various issues in unarj. Please see the advisory in Web references for more information.
Debian has released an advisory (DSA 652-1) to address issues in unarj. Please see the advisory in the reference section for more information.
Avaya has released advisory ASA-2005-022 to document the affected versions of Avaya products. Please see the referenced advisory for further information.
Fedora has released an advisory (Fedora Legacy Update Advisory FLSA:2272) to address unarj issues in Red Hat Linux 7.3 - i386, Red Hat Linux 9 - i386, and Fedora Core 1 - i386. Please see the referenced advisory for more information.
ARJ Software Inc. UNARJ 2.43
ARJ Software Inc. UNARJ 2.63 a
Solution:
RedHat Fedora Linux has released advisory FEDORA-2004-414 along with fixes dealing with this and another issue. Please see the referenced advisory for more information.
Gentoo Linux has released advisory GLSA 200411-29 to address this issue. Users of affected packages are urged to execute the following commands with superuser privileges:
emerge --sync
emerge --ask --oneshot --verbose ">=app-arch/unarj-2.63a-r2"
Please see the referenced advisory for further information.
Red Hat has released an advisory (RHSA-2005:007-05) to address various issues in unarj. Please see the advisory in Web references for more information.
Debian has released an advisory (DSA 652-1) to address issues in unarj. Please see the advisory in the reference section for more information.
Avaya has released advisory ASA-2005-022 to document the affected versions of Avaya products. Please see the referenced advisory for further information.
Fedora has released an advisory (Fedora Legacy Update Advisory FLSA:2272) to address unarj issues in Red Hat Linux 7.3 - i386, Red Hat Linux 9 - i386, and Fedora Core 1 - i386. Please see the referenced advisory for more information.
ARJ Software Inc. UNARJ 2.43
-
Debian unarj_2.43-3woody1_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/u/unarj/unarj_2.43-3w oody1_alpha.deb -
Debian unarj_2.43-3woody1_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/u/unarj/unarj_2.43-3w oody1_arm.deb -
Debian unarj_2.43-3woody1_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/u/unarj/unarj_2.43-3w oody1_hppa.deb -
Debian unarj_2.43-3woody1_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/u/unarj/unarj_2.43-3w oody1_i386.deb -
Debian unarj_2.43-3woody1_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/u/unarj/unarj_2.43-3w oody1_ia64.deb -
Debian unarj_2.43-3woody1_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/u/unarj/unarj_2.43-3w oody1_m68k.deb -
Debian unarj_2.43-3woody1_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/u/unarj/unarj_2.43-3w oody1_powerpc.deb -
Debian unarj_2.43-3woody1_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/u/unarj/unarj_2.43-3w oody1_s390.deb -
Debian unarj_2.43-3woody1_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/u/unarj/unarj_2.43-3w oody1_sparc.deb -
RedHat unarj-2.63a-4.0.7.3.1.legacy.i386.rpm
http://download.fedoralegacy.org/redhat/7.3/updates/i386/unarj-2.63a-4 .0.7.3.1.legacy.i386.rpm
ARJ Software Inc. UNARJ 2.63 a
-
Fedora unarj-2.63a-7.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora unarj-2.63a-7.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora unarj-debuginfo-2.63a-7.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora unarj-debuginfo-2.63a-7.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
RedHat unarj-2.63a-4.0.9.1.legacy.i386.rpm
http://download.fedoralegacy.org/redhat/9/updates/i386/unarj-2.63a-4.0 .9.1.legacy.i386.rpm -
RedHat unarj-2.63a-4.1.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/1/updates/i386/unarj-2.63a-4.1 .1.legacy.i386.rpm
References
ARJ Software UNARJ Remote Directory Traversal Vulnerability
References:
References:
- ARJ Software Home Page (ARJ Software Inc.)
- ASA-2005-022_RHSA-2005-007 (Avaya)
- RHSA-2005:007-05 - unarj (RedHat)