'libarchive' Multiple Remote Vulnerabilities
BID:24885
Info
'libarchive' Multiple Remote Vulnerabilities
| Bugtraq ID: | 24885 |
| Class: | Unknown |
| CVE: |
CVE-2007-3641 CVE-2007-3644 CVE-2007-3645 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 12 2007 12:00AM |
| Updated: | Mar 24 2008 06:20PM |
| Credit: | CPNI, CERT-FI, Tim Kientzle, and Colin Percival are credited with the discovery of these issues. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 9 SP3 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise SDK 9 SuSE SUSE Linux Enterprise SDK 10.SP1 SuSE SUSE Linux Enterprise SDK 10 SuSE SUSE Linux Enterprise SDK 10 SuSE Suse Linux Enterprise Desktop 10 SP1 SuSE Suse Linux Enterprise Desktop 10 SuSE Linux Enterprise Server 10.SP1 SuSE Linux Enterprise Server 10 SuSE Linux 10.1 x86-64 SuSE Linux 10.1 x86 SuSE Linux 10.1 ppc SuSE Linux 10.0 x86-64 SuSE Linux 10.0 x86 SuSE Linux 10.0 ppc S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 1 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop 9 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 10.1 Gentoo Linux FreeBSD FreeBSD 6.0 .x FreeBSD FreeBSD 6.0 -STABLE FreeBSD FreeBSD 6.0 -RELEASE FreeBSD FreeBSD 5.5 -STABLE FreeBSD FreeBSD 5.5 -RELEASE FreeBSD FreeBSD 5.4 -RELENG FreeBSD FreeBSD 5.4 -RELEASE FreeBSD FreeBSD 5.4 -PRERELEASE FreeBSD FreeBSD 5.3 -STABLE FreeBSD FreeBSD 5.3 -RELENG FreeBSD FreeBSD 5.3 -RELEASE FreeBSD FreeBSD 5.3 FreeBSD FreeBSD 6.2 -STABLE FreeBSD FreeBSD 6.2 FreeBSD FreeBSD 6.1 -STABLE FreeBSD FreeBSD 6.1 -RELEASE-p10 FreeBSD FreeBSD 6.1 -RELEASE FreeBSD FreeBSD 6.0 -RELEASE-p5 FreeBSD FreeBSD 5.4-STABLE Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: | |
Discussion
'libarchive' Multiple Remote Vulnerabilities
The 'libarchive' library is prone to multiple vulnerabilities because it fails to properly handle malformed TAR and PAX archives.
Successfully exploiting these issues allows remote attackers to trigger application crashes, consume excessive CPU resources, and potentially execute arbitrary machine code in the context of applications that use the affected library.
The 'libarchive' library is prone to multiple vulnerabilities because it fails to properly handle malformed TAR and PAX archives.
Successfully exploiting these issues allows remote attackers to trigger application crashes, consume excessive CPU resources, and potentially execute arbitrary machine code in the context of applications that use the affected library.
Exploit / POC
'libarchive' Multiple Remote Vulnerabilities
To exploit these vulnerabilities, an attacker must entice a victim to open a corrupted archive file.
Proof-of-concept archive files are available from the University of Oulu at the following URI:
http://www.ee.oulu.fi/research/ouspg/protos/testing/c10/archive/
To exploit these vulnerabilities, an attacker must entice a victim to open a corrupted archive file.
Proof-of-concept archive files are available from the University of Oulu at the following URI:
http://www.ee.oulu.fi/research/ouspg/protos/testing/c10/archive/
Solution / Fix
'libarchive' Multiple Remote Vulnerabilities
Solution:
Please see the referenced advisories for information on how to obtain and apply fixes.
FreeBSD FreeBSD 6.1 -RELEASE
FreeBSD FreeBSD 6.1 -STABLE
FreeBSD FreeBSD 6.2
FreeBSD FreeBSD 6.1 -RELEASE-p10
FreeBSD FreeBSD 6.2 -STABLE
FreeBSD FreeBSD 5.5 -RELEASE
FreeBSD FreeBSD 5.5 -STABLE
Solution:
Please see the referenced advisories for information on how to obtain and apply fixes.
FreeBSD FreeBSD 6.1 -RELEASE
-
FreeBSD libarchive.patch
http://security.freebsd.org/patches/SA-07:05/libarchive.patch
FreeBSD FreeBSD 6.1 -STABLE
-
FreeBSD libarchive.patch
http://security.freebsd.org/patches/SA-07:05/libarchive.patch
FreeBSD FreeBSD 6.2
-
FreeBSD libarchive.patch
http://security.freebsd.org/patches/SA-07:05/libarchive.patch
FreeBSD FreeBSD 6.1 -RELEASE-p10
-
FreeBSD libarchive.patch
http://security.freebsd.org/patches/SA-07:05/libarchive.patch
FreeBSD FreeBSD 6.2 -STABLE
-
FreeBSD libarchive.patch
http://security.freebsd.org/patches/SA-07:05/libarchive.patch
FreeBSD FreeBSD 5.5 -RELEASE
-
FreeBSD libarchive.patch
http://security.freebsd.org/patches/SA-07:05/libarchive.patch
FreeBSD FreeBSD 5.5 -STABLE
-
FreeBSD libarchive.patch
http://security.freebsd.org/patches/SA-07:05/libarchive.patch
References
'libarchive' Multiple Remote Vulnerabilities
References:
References:
- FreeBSD Homepage (FreeBSD)
- PROTOS Genome Test Suite c10-archive (Oulu University)
- 20469: CERT-FI and CPNI Joint Vulnerability Advisory on Archive Formats (CERT-FI)
- Vulnerability Note VU#970849 libarchive does not properly terminate loop (US-CERT)