Multiple Vendor UNACEV2 Archive File Name Buffer Overflow Vulnerability
BID:14759
Info
Multiple Vendor UNACEV2 Archive File Name Buffer Overflow Vulnerability
| Bugtraq ID: | 14759 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-2856 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 07 2005 12:00AM |
| Updated: | Sep 07 2006 09:53PM |
| Credit: | Discovery is credited to Tan Chew Keong. |
| Vulnerable: |
WinHKI WinHKI 1.67 WinHKI WinHKI 1.66 Where Is It Soft Where Is It 3.73.501 UltimateZip UltimateZip 3.0.3 UltimateZip UltimateZip 2.7.1 UltimateZip UltimateZip 3.1b Rising Antivirus International Rising Antivirus 2006 18.27.21 Rising Antivirus International Rising Antivirus 2006 18.25.40 Rising Antivirus International Rising Antivirus 2006 18.25.30 Rising Antivirus International Rising Antivirus 2006 18.24.10 Network Automation AutoMate 6.1 .0 Nathan Moinvaziri ExtractNow 3.60 Microchip Data Systems ZipTV for Delphi 7 2006.1.26 Microchip Data Systems ZipTV for C++ Builder 2006.1.16 Ivan Zahariev IZArc 3.5 beta 3 FilZip FilZip 3.04 Eazel Eazel 1.0 ConeXware PowerArchiver 9.60 Bitberry Software BitZipper 4.1 SR-1 ALTools ALZip 6.11 (Korean) ALTools ALZip 6.1 beta ALTools ALZip 6.0 3 (English) ALTools ALZip 5.52 ALTools ALZip 5.51 a-squared Anti-Trojan 5.5.421 |
| Not Vulnerable: |
WinHKI WinHKI 1.68 Where Is It Soft Where Is It 3.73.505 Rising Antivirus International Rising Antivirus 2006 18.29.12 Nathan Moinvaziri ExtractNow 4.16 ConeXware PowerArchiver 9.61 ALTools ALZip 6.12 (Korean) ALTools ALZip 6.1 |
Discussion
Multiple Vendor UNACEV2 Archive File Name Buffer Overflow Vulnerability
Multiple products are prone to a buffer overflow when handling ACE archives that contain files with overly long names.
This may be exploited to execute arbitrary code in the context of the user who is running the application. The vulnerability is considered remotely exploitable in nature because malicious ACE archives will likely originate from an external, untrusted source.
Multiple products are prone to a buffer overflow when handling ACE archives that contain files with overly long names.
This may be exploited to execute arbitrary code in the context of the user who is running the application. The vulnerability is considered remotely exploitable in nature because malicious ACE archives will likely originate from an external, untrusted source.
Exploit / POC
Multiple Vendor UNACEV2 Archive File Name Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Multiple Vendor UNACEV2 Archive File Name Buffer Overflow Vulnerability
Solution:
This issue has been addressed in ALZip 6.1 for English and international versions other than Korean. ALZip 6.12 (Korean) addresses the Korean-language release.
This issue has been addressed in WinHKI version 1.68.
This issue is not present in the 4.x series of ExtractNow.
NOTE: a-squared Anti-Trojan is no longer supported. Users of affected Anti-Trojan products are encouraged to upgrade to its successor software, Anti-Malware.
ConeXware PowerArchiver version 9.61 (and later) contains a fix for this issue.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please email us at: [email protected]:[email protected].
WinHKI WinHKI 1.66
Nathan Moinvaziri ExtractNow 3.60
WinHKI WinHKI 1.67
Where Is It Soft Where Is It 3.73.501
ALTools ALZip 5.51
ALTools ALZip 5.52
ALTools ALZip 6.0 3 (English)
ALTools ALZip 6.1 beta
ALTools ALZip 6.11 (Korean)
Solution:
This issue has been addressed in ALZip 6.1 for English and international versions other than Korean. ALZip 6.12 (Korean) addresses the Korean-language release.
This issue has been addressed in WinHKI version 1.68.
This issue is not present in the 4.x series of ExtractNow.
NOTE: a-squared Anti-Trojan is no longer supported. Users of affected Anti-Trojan products are encouraged to upgrade to its successor software, Anti-Malware.
ConeXware PowerArchiver version 9.61 (and later) contains a fix for this issue.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please email us at: [email protected]:[email protected].
WinHKI WinHKI 1.66
-
WinHKI Latest Release
http://www.winhki.com/download/setuphki.exe
Nathan Moinvaziri ExtractNow 3.60
-
Nathan Moinvaziri ExtractNow Latest Version Download
http://www.extractnow.com/extractnow.exe
WinHKI WinHKI 1.67
-
WinHKI Latest Release
http://www.winhki.com/download/setuphki.exe
Where Is It Soft Where Is It 3.73.501
-
Where Is It Soft Where Is It 3.73.505
http://www.whereisit-soft.com/download.html
ALTools ALZip 5.51
-
ALTools ALZip 6.1
http://www.altools.net/Portals/0/ALZip.exe
ALTools ALZip 5.52
-
ALTools ALZip 6.1
http://www.altools.net/Portals/0/ALZip.exe
ALTools ALZip 6.0 3 (English)
-
ALTools ALZip 6.1
http://www.altools.net/Portals/0/ALZip.exe
ALTools ALZip 6.1 beta
-
ALTools ALZip 6.1
http://www.altools.net/Portals/0/ALZip.exe
ALTools ALZip 6.11 (Korean)
-
ALTools ALZip 6.12 (Korean)
http://down.altools.com/ALZip612.exe
References
Multiple Vendor UNACEV2 Archive File Name Buffer Overflow Vulnerability
References:
References:
- Secunia Research: BitZipper unacev2.dll Buffer Overflow Vulnerability (Secunia Research
) - a-squared Home Page (a-squared)
- ALTools Homepage (ALTools)
- ALZip ACE Archive Handling Buffer Overflow (Secunia Research)
- AutoMate 6 / The Next Generation Automation Platform (Network Automation)
- Eazel Home Page (Eazel)
- ExtractNow Home Page (Nathan Moinvaziri)
- ExtractNow unacev2.dll Buffer Overflow Vulnerability (Secunia)
- IZArc Homepage (Ivan Zahariev)
- PowerArchiver Download Page (ConeXware)
- PowerArchiver Home Page (ConeXware)
- PowerArchiver unacev2.dll Buffer Overflow Vulnerability (Secunia)
- Rising Antivirus unacev2.dll Buffer Overflow Vulnerability (Secunia)
- Secunia Research: AutoMate unacev2.dll Buffer Overflow Vulnerability (Secunia)
- WinHKI Home Page (WinHKI)
- ZipTV ARJ Archive Handling and unacev2.dll Buffer Overflows (Secunia)
- ZipTV Home Page (Microchip Data Systems)
- Secunia Research: Anti-Trojan unacev2.dll Buffer Overflow Vulnerability (Secunia Research
) - Secunia Research: AutoMate unacev2.dll Buffer Overflow Vulnerability (Secunia Research
) - Secunia Research: FilZip unacev2.dll Buffer Overflow Vulnerability (Secunia Research
) - Secunia Research: Where Is It unacev2.dll Buffer Overflow Vulnerability (Secunia Research
) - Secunia Research: WinHKI unacev2.dll Buffer Overflow Vulnerability (Secunia Research
)