Info-ZIP UnZip File Name Buffer Overflow Vulnerability
BID:15968
Info
Info-ZIP UnZip File Name Buffer Overflow Vulnerability
| Bugtraq ID: | 15968 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-4667 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 19 2005 12:00AM |
| Updated: | Sep 19 2007 10:30PM |
| Credit: | c0ntex <[email protected]> disclosed this vulnerability. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.10 powerpc Ubuntu Ubuntu Linux 5.10 i386 Ubuntu Ubuntu Linux 5.10 amd64 Ubuntu Ubuntu Linux 5.0 4 powerpc Ubuntu Ubuntu Linux 5.0 4 i386 Ubuntu Ubuntu Linux 5.0 4 amd64 Ubuntu Ubuntu Linux 4.1 ppc Ubuntu Ubuntu Linux 4.1 ia64 Ubuntu Ubuntu Linux 4.1 ia32 Trustix Secure Linux 3.0 Trustix Secure Linux 2.2 Trustix Secure Enterprise Linux 2.0 Redhat Linux 9.0 i386 Redhat Linux 7.3 i386 Redhat Fedora Core3 Redhat Fedora Core2 Redhat Fedora Core1 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux AS 4 Redhat Desktop 4.0 Mandriva Linux Mandrake 2006.0 x86_64 Mandriva Linux Mandrake 2006.0 Mandriva Linux Mandrake 10.2 x86_64 Mandriva Linux Mandrake 10.2 MandrakeSoft Multi Network Firewall 2.0 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 Info-ZIP UnZip 5.52 Info-ZIP UnZip 5.51 Info-ZIP UnZip 5.50 Info-ZIP UnZip 5.42 Info-ZIP UnZip 5.41 Info-ZIP UnZip 5.40 Info-ZIP UnZip 5.32 Info-ZIP UnZip 5.31 Info-ZIP UnZip 5.3 Info-ZIP UnZip 5.2 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 Avaya Messaging Storage Server MSS 3.0 Avaya Message Networking MN 3.1 Avaya Message Networking Avaya IA770 Voice Mail 0 Avaya Aura Application Enablement Services 4.0.1 Avaya Aura Application Enablement Services 3.1.3 Avaya Aura Application Enablement Services 3.0 Avaya AES 4.0 Avaya AES 3.1 |
| Not Vulnerable: | |
Discussion
Info-ZIP UnZip File Name Buffer Overflow Vulnerability
Info-ZIP 'unzip' is susceptible to a filename buffer-overflow vulnerability. The application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
This issue allows attackers to execute arbitrary machine code in the context of users running the affected application.
Info-ZIP 'unzip' is susceptible to a filename buffer-overflow vulnerability. The application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
This issue allows attackers to execute arbitrary machine code in the context of users running the affected application.
Exploit / POC
Info-ZIP UnZip File Name Buffer Overflow Vulnerability
The following example command will demonstrate this issue:
unzip `perl -e 'print "A" x 50000'`
An exploit by DVDMAN is available:
The following example command will demonstrate this issue:
unzip `perl -e 'print "A" x 50000'`
An exploit by DVDMAN is available:
Solution / Fix
Info-ZIP UnZip File Name Buffer Overflow Vulnerability
Solution:
Please see the referenced vendor advisories for details on obtaining and applying fixes.
Info-ZIP UnZip 5.50
Info-ZIP UnZip 5.51
Info-ZIP UnZip 5.52
Solution:
Please see the referenced vendor advisories for details on obtaining and applying fixes.
Info-ZIP UnZip 5.50
-
Debian unzip_5.50-1woody6_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody 6_alpha.deb -
Debian unzip_5.50-1woody6_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody 6_arm.deb -
Debian unzip_5.50-1woody6_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody 6_hppa.deb -
Debian unzip_5.50-1woody6_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody 6_i386.deb -
Debian unzip_5.50-1woody6_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody 6_ia64.deb -
Debian unzip_5.50-1woody6_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody 6_m68k.deb -
Debian unzip_5.50-1woody6_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody 6_mips.deb -
Debian unzip_5.50-1woody6_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody 6_mipsel.deb -
Debian unzip_5.50-1woody6_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody 6_powerpc.deb -
Debian unzip_5.50-1woody6_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody 6_s390.deb -
Debian unzip_5.50-1woody6_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody 6_sparc.deb -
Mandrake unzip-5.50-9.3.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandrake unzip-5.50-9.3.C30mdk.x86_64.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandrake unzip-5.50-9.3.M20mdk.i586.
Multi Network Firewall 2.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandrake unzip-5.50-9.3.M20mdk.i586.rpm
Multi Network Firewall 2.0:
http://wwwnew.mandriva.com/en/downloads/ -
RedHat unzip-5.50-31.1.legacy.i386.rpm
Red Hat Linux 7.3:
http://download.fedoralegacy.org/redhat/7.3/updates/i386/unzip-5.50-31 .1.legacy.i386.rpm -
RedHat unzip-5.50-33.1.legacy.i386.rpm
Red Hat Linux 9:
http://download.fedoralegacy.org/redhat/9/updates/i386/unzip-5.50-33.1 .legacy.i386.rpm -
RedHat unzip-5.50-35.1.legacy.i386.rpm
Fedora Core 1:
http://download.fedoralegacy.org/fedora/1/updates/i386/unzip-5.50-35.1 .legacy.i386.rpm -
RedHat unzip-5.50-37.1.legacy.i386.rpm
Fedora Core 2:
http://download.fedoralegacy.org/fedora/2/updates/i386/unzip-5.50-37.1 .legacy.i386.rpm
Info-ZIP UnZip 5.51
-
Mandrake unzip-5.51-1.3.102mdk.i586.rpm
Mandriva Linux 10.2:
http://wwwnew.mandriva.com/en/downloads/ -
Mandrake unzip-5.51-1.3.102mdk.x86_64.rpm
Mandriva Linux 10.2:
http://wwwnew.mandriva.com/en/downloads/ -
RedHat unzip-5.51-4.fc3.1.legacy.i386.rpm
Fedora Core 3:
http://download.fedoralegacy.org/fedora/3/updates/i386/unzip-5.51-4.fc 3.1.legacy.i386.rpm -
RedHat unzip-5.51-4.fc3.1.legacy.x86_64.rpm
Fedora Core 3:
http://download.fedoralegacy.org/fedora/3/updates/x86_64/unzip-5.51-4. fc3.1.legacy.x86_64.rpm
Info-ZIP UnZip 5.52
-
Debian unzip_5.52-1sarge4_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.52-1sarge 4_alpha.deb -
Debian unzip_5.52-1sarge4_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.52-1sarge 4_amd64.deb -
Debian unzip_5.52-1sarge4_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.52-1sarge 4_arm.deb -
Debian unzip_5.52-1sarge4_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.52-1sarge 4_hppa.deb -
Debian unzip_5.52-1sarge4_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.52-1sarge 4_i386.deb -
Debian unzip_5.52-1sarge4_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.52-1sarge 4_ia64.deb -
Debian unzip_5.52-1sarge4_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.52-1sarge 4_m68k.deb -
Debian unzip_5.52-1sarge4_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.52-1sarge 4_mips.deb -
Debian unzip_5.52-1sarge4_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.52-1sarge 4_mipsel.deb -
Debian unzip_5.52-1sarge4_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.52-1sarge 4_powerpc.deb -
Debian unzip_5.52-1sarge4_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.52-1sarge 4_s390.deb -
Debian unzip_5.52-1sarge4_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.52-1sarge 4_sparc.deb -
Mandrake unzip-5.52-1.3.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandrake unzip-5.52-1.3.20060mdk.x86_64.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads/
References
Info-ZIP UnZip File Name Buffer Overflow Vulnerability
References:
References: