Microsoft Windows 98/ME/XP File Decompression Vulnerabilities
BID:5870
Info
Microsoft Windows 98/ME/XP File Decompression Vulnerabilities
| Bugtraq ID: | 5870 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 02 2002 12:00AM |
| Updated: | Oct 02 2002 12:00AM |
| Credit: | Discovery of these issues is credited to Joe Testa of Rapid7, Inc. and zen-parse. |
| Vulnerable: |
Microsoft Windows XP Home SP1 Microsoft Windows XP Home Microsoft Windows ME Microsoft Windows 98 With Plus! Pack |
| Not Vulnerable: | |
Discussion
Microsoft Windows 98/ME/XP File Decompression Vulnerabilities
Microsoft Windows 98 with Plus! Pack, Windows ME, and Windows XP are all prone to multiple vulnerabilities related to the Compressed Folders feature.
The Compressed Folders feature allows zipped archives to be treated as folders.
The first issue is a buffer overflow that may be trigged by a malformed filename when a file is being decompressed from a zipped archive. The vulnerability may be exploited to execute arbitrary code as the user decompressing the archive containing the maliciously named file.
The second issue may allow an attacker to specify a hostile path for files when a zipped archive is decompressed. A flaw in the decompression function may allow an attacker to cause a file to be decompressed in a directory that is neither the user-specified directory or a child of the user-specified directory.
Exploitation of both these issues still requires user interaction, as the victim of the attacker may still decompress a malicious zipped file.
Microsoft Windows 98 with Plus! Pack, Windows ME, and Windows XP are all prone to multiple vulnerabilities related to the Compressed Folders feature.
The Compressed Folders feature allows zipped archives to be treated as folders.
The first issue is a buffer overflow that may be trigged by a malformed filename when a file is being decompressed from a zipped archive. The vulnerability may be exploited to execute arbitrary code as the user decompressing the archive containing the maliciously named file.
The second issue may allow an attacker to specify a hostile path for files when a zipped archive is decompressed. A flaw in the decompression function may allow an attacker to cause a file to be decompressed in a directory that is neither the user-specified directory or a child of the user-specified directory.
Exploitation of both these issues still requires user interaction, as the victim of the attacker may still decompress a malicious zipped file.
Exploit / POC
Microsoft Windows 98/ME/XP File Decompression Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft Windows 98/ME/XP File Decompression Vulnerabilities
Solution:
Microsoft has incorporated the fix for the malformed filename buffer overflow into Windows XP SP1. Windows ME may only be updated using Windows Update.
Patches are available:
Microsoft Windows XP Home
Microsoft Windows XP Home SP1
Microsoft Windows 98 With Plus! Pack
Solution:
Microsoft has incorporated the fix for the malformed filename buffer overflow into Windows XP SP1. Windows ME may only be updated using Windows Update.
Patches are available:
Microsoft Windows XP Home
-
Microsoft Q329048
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=43419
Microsoft Windows XP Home SP1
-
Microsoft Q329048
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=43419
Microsoft Windows 98 With Plus! Pack
References
Microsoft Windows 98/ME/XP File Decompression Vulnerabilities
References:
References:
- Microsoft Security Bulletin MS02-054 (Microsoft)