ARJ Software UNARJ Remote Buffer Overflow Vulnerability
BID:11665
Info
ARJ Software UNARJ Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 11665 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-0947 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 12 2004 12:00AM |
| Updated: | Jul 12 2009 08:06AM |
| Credit: | The individual or individuals responsible for disclosure of these issues are currently unknown; these issues were disclosed in the referenced RedHat Fedora advisory. |
| Vulnerable: |
S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 2.1 Redhat Advanced Workstation for the Itanium Processor 2.1 Gentoo Linux Avaya CVLAN ARJ Software Inc. UNARJ 2.65 ARJ Software Inc. UNARJ 2.64 ARJ Software Inc. UNARJ 2.63 a ARJ Software Inc. UNARJ 2.62 ARJ Software Inc. UNARJ 2.43 |
| Not Vulnerable: | |
Discussion
ARJ Software UNARJ Remote Buffer Overflow Vulnerability
A remote buffer-overflow vulnerability affects ARJ Software's unarj. This issue is caused by the application's failure to carry out sufficient bounds checking on user-supplied strings prior to processing.
A remote attacker may leverage this issue to execute arbitrary code with the privileges of a user that processes a malicious file with the affected application. This may facilitate unauthorized access or privilege escalation.
A remote buffer-overflow vulnerability affects ARJ Software's unarj. This issue is caused by the application's failure to carry out sufficient bounds checking on user-supplied strings prior to processing.
A remote attacker may leverage this issue to execute arbitrary code with the privileges of a user that processes a malicious file with the affected application. This may facilitate unauthorized access or privilege escalation.
Exploit / POC
ARJ Software UNARJ Remote Buffer Overflow Vulnerability
This vulnerability can be tested using the PIRANA exploitation framework available at the following location:
http://www.guay-leroux.com/projects/pirana-0.2.1.tar.gz
This vulnerability can be tested using the PIRANA exploitation framework available at the following location:
http://www.guay-leroux.com/projects/pirana-0.2.1.tar.gz
Solution / Fix
ARJ Software UNARJ Remote Buffer Overflow Vulnerability
Solution:
Please see the referenced advisories for more information.
ARJ Software Inc. UNARJ 2.43
ARJ Software Inc. UNARJ 2.63 a
S.u.S.E. Linux Personal 9.0
S.u.S.E. Linux Personal 9.1
S.u.S.E. Linux Personal 9.2
Solution:
Please see the referenced advisories for more information.
ARJ Software Inc. UNARJ 2.43
-
Debian unarj_2.43-3woody1_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/u/unarj/unarj_2.43-3w oody1_alpha.deb -
Debian unarj_2.43-3woody1_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/u/unarj/unarj_2.43-3w oody1_arm.deb -
Debian unarj_2.43-3woody1_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/u/unarj/unarj_2.43-3w oody1_hppa.deb -
Debian unarj_2.43-3woody1_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/u/unarj/unarj_2.43-3w oody1_i386.deb -
Debian unarj_2.43-3woody1_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/u/unarj/unarj_2.43-3w oody1_ia64.deb -
Debian unarj_2.43-3woody1_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/u/unarj/unarj_2.43-3w oody1_m68k.deb -
Debian unarj_2.43-3woody1_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/u/unarj/unarj_2.43-3w oody1_powerpc.deb -
Debian unarj_2.43-3woody1_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/u/unarj/unarj_2.43-3w oody1_s390.deb -
Debian unarj_2.43-3woody1_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/u/unarj/unarj_2.43-3w oody1_sparc.deb -
RedHat unarj-2.63a-4.0.7.3.1.legacy.i386.rpm
http://download.fedoralegacy.org/redhat/7.3/updates/i386/unarj-2.63a-4 .0.7.3.1.legacy.i386.rpm
ARJ Software Inc. UNARJ 2.63 a
-
Fedora unarj-2.63a-7.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora unarj-2.63a-7.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora unarj-debuginfo-2.63a-7.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora unarj-debuginfo-2.63a-7.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
RedHat unarj-2.63a-4.0.9.1.legacy.i386.rpm
http://download.fedoralegacy.org/redhat/9/updates/i386/unarj-2.63a-4.0 .9.1.legacy.i386.rpm -
RedHat unarj-2.63a-4.1.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/1/updates/i386/unarj-2.63a-4.1 .1.legacy.i386.rpm
S.u.S.E. Linux Personal 9.0
-
SuSE unarj-2.65-137.i586.rpm
x86
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/unarj-2.65-137.i5 86.rpm -
SuSE unarj-2.65-137.x86_64.rpm
x86
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/unarj-2.65-13 7.x86_64.rpm
S.u.S.E. Linux Personal 9.1
-
SuSE unarj-2.65-131.6.i586.rpm
x86
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/unarj-2.65-131.6. i586.rpm -
SuSE unarj-2.65-131.6.x86_64.rpm
x86-64
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/unarj-2.65-13 1.6.x86_64.rpm
S.u.S.E. Linux Personal 9.2
-
SuSE unarj-2.65-133.3.i586.rpm
ix86 fix
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/unarj-2.65-133.3. i586.rpm -
SuSE unarj-2.65-133.3.x86_64.rpm
x86-64 fix
ftp://ftp.suse.com/pub/suse/x86_64/update/9.2/rpm/x86_64/unarj-2.65-13 3.3.x86_64.rpm
References
ARJ Software UNARJ Remote Buffer Overflow Vulnerability
References:
References:
- ARJ Software Home Page (ARJ Software Inc.)
- ASA-2005-022_RHSA-2005-007 (Avaya)
- RHSA-2005:007-05 - unarj (RedHat)