7-Zip Unspecified Archive Handling Vulnerability
BID:28285
Info
7-Zip Unspecified Archive Handling Vulnerability
| Bugtraq ID: | 28285 |
| Class: | Unknown |
| CVE: |
CVE-2008-6536 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 17 2008 12:00AM |
| Updated: | Apr 13 2015 09:41PM |
| Credit: | The University of Oulu discovered this issue. |
| Vulnerable: |
Xerox FreeFlow Print Server (FFPS) 73.C5.11 Xerox FreeFlow Print Server (FFPS) 73.C0.41 Xerox FreeFlow Print Server (FFPS) 73.B3.61 Sun Solaris 9_x86 Update 5 Sun Solaris 9_x86 Update 2 Sun Solaris 9_x86 Sun Solaris 9_sparc Sun Solaris 9 Update 5 Sun Solaris 9 Express Sun Solaris 9 Sun Solaris 10_x86 Sun Solaris 10_sparc Sun Solaris 10 Express Sun Solaris 10 7-Zip 7-Zip 4.27 BETA 7-Zip 7-Zip 4.26 BETA 7-Zip 7-Zip 4.23 7-Zip 7-Zip 3.13 7-Zip 7-Zip 4.57 7-Zip 7-Zip 3.30 |
| Not Vulnerable: |
7-Zip 7-Zip 4.57 |
Discussion
7-Zip Unspecified Archive Handling Vulnerability
7-Zip prone to a remote archive-handling vulnerability because the application fails to properly handle malformed archive files.
Successfully exploiting this issue may allow remote attackers to execute code, but this has not been confirmed. Exploit attempts will likely crash the application.
Versions prior to 7-Zip 4.57 are affected.
7-Zip prone to a remote archive-handling vulnerability because the application fails to properly handle malformed archive files.
Successfully exploiting this issue may allow remote attackers to execute code, but this has not been confirmed. Exploit attempts will likely crash the application.
Versions prior to 7-Zip 4.57 are affected.
Exploit / POC
7-Zip Unspecified Archive Handling Vulnerability
The Oulu University Secure Programming Group (OUSPG) at the University of Oulu in Finland created archive files designed to trigger this issue. The archive files may be obtained from the following URI:
http://www.ee.oulu.fi/research/ouspg/protos/testing/c10/archive/
The Oulu University Secure Programming Group (OUSPG) at the University of Oulu in Finland created archive files designed to trigger this issue. The archive files may be obtained from the following URI:
http://www.ee.oulu.fi/research/ouspg/protos/testing/c10/archive/
Solution / Fix
7-Zip Unspecified Archive Handling Vulnerability
Solution:
The vendor has released fixes to address this issue. Please see the references for more information.
7-Zip 7-Zip 3.30
7-Zip 7-Zip 3.13
7-Zip 7-Zip 4.23
7-Zip 7-Zip 4.26 BETA
7-Zip 7-Zip 4.27 BETA
Solution:
The vendor has released fixes to address this issue. Please see the references for more information.
7-Zip 7-Zip 3.30
-
7-Zip 7z457.tar.bz2
http://downloads.sourceforge.net/sevenzip/7z457.tar.bz2
7-Zip 7-Zip 3.13
-
7-Zip 7z457.tar.bz2
http://downloads.sourceforge.net/sevenzip/7z457.tar.bz2
7-Zip 7-Zip 4.23
-
7-Zip 7z457.tar.bz2
http://downloads.sourceforge.net/sevenzip/7z457.tar.bz2
7-Zip 7-Zip 4.26 BETA
-
7-Zip 7z457.tar.bz2
http://downloads.sourceforge.net/sevenzip/7z457.tar.bz2
7-Zip 7-Zip 4.27 BETA
-
7-Zip 7z457.tar.bz2
http://downloads.sourceforge.net/sevenzip/7z457.tar.bz2
References
7-Zip Unspecified Archive Handling Vulnerability
References:
References:
- 7-Zip Home Page (7-Zip )
- CVE-2008-6536 Unspecified vulnerability in 7-zip (Oracle)
- PROTOS Genome Test Suite c10-archive (Oulu University)
- Xerox Security Bulletin XRX13-003 (Xerox)
- 20469: CERT-FI and CPNI Joint Vulnerability Advisory on Archive Formats (CERT-FI)
- Xerox Security Bulletin XRX13-004 (Xerox)