StuffIt and ZipMagic Remote Directory Traversal Vulnerability
BID:16806
Info
StuffIt and ZipMagic Remote Directory Traversal Vulnerability
| Bugtraq ID: | 16806 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 24 2006 12:00AM |
| Updated: | Feb 27 2006 04:01PM |
| Credit: | Hamid Ebadi is credited with the discovery of this vulnerability. |
| Vulnerable: |
SmithMicro ZipMagic Deluxe 9.0 SmithMicro StuffIt Standard 9.0 SmithMicro StuffIt Expander 9.0 SmithMicro StuffIt Deluxe 9.0 |
| Not Vulnerable: | |
Discussion
StuffIt and ZipMagic Remote Directory Traversal Vulnerability
Reportedly, an attacker can carry out attacks similar to directory traversals. These issues present themselves when the application processes malicious archives.
A successful attack can allow the attacker to place potentially malicious files and overwrite files on a computer in the context of the user running the affected application. Successful exploitation may aid in further attacks.
Reportedly, an attacker can carry out attacks similar to directory traversals. These issues present themselves when the application processes malicious archives.
A successful attack can allow the attacker to place potentially malicious files and overwrite files on a computer in the context of the user running the affected application. Successful exploitation may aid in further attacks.
Exploit / POC
StuffIt and ZipMagic Remote Directory Traversal Vulnerability
This issue can be exploited by creating a malicious archive file that includes files with directory traversal strings '../' in the names.
This issue can be exploited by creating a malicious archive file that includes files with directory traversal strings '../' in the names.
Solution / Fix
StuffIt and ZipMagic Remote Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
References
StuffIt and ZipMagic Remote Directory Traversal Vulnerability
References:
References:
- Directory traversal vulnerabilities in .zip .tar .rar (Hamid)
- StuffIt and ZipMagic Family of products Directory traversal (Hamid)
- StuffIt Homepage (SmithMicro)
- ZipMagic Homepage (SmithMicro)
- StuffIt and ZipMagic Family of products Directory traversal (Hamid)