Multiple Vendor ZIP Files Long Filename Buffer Overflow Vulnerability
BID:5873
Info
Multiple Vendor ZIP Files Long Filename Buffer Overflow Vulnerability
| Bugtraq ID: | 5873 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0370 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 03 2002 12:00AM |
| Updated: | Jul 11 2009 05:06PM |
| Credit: | Discovery of this vulnerability is credited to Joe Testa of Rapid7, Inc. |
| Vulnerable: |
WinZip WinZip 7.0 Verity Inc. KeyView Viewing SDK Microsoft Windows XP Professional SP1 Microsoft Windows XP Professional Microsoft Windows XP Home SP1 Microsoft Windows XP Home Microsoft Windows ME Microsoft Windows 98 With Plus! Pack Lotus Notes Client 5.0.11 Lotus Notes Client 5.0.10 Lotus Notes Client 5.0.9 a Lotus Notes Client 5.0.5 Lotus Notes Client 5.0.4 Lotus Notes Client 5.0.3 Lotus Notes Client 5.0.2 Lotus Notes Client 5.0.1 Lotus Notes Client 5.0 Lotus Notes Client 4.5 Lotus Notes Client R6 Lotus Notes Client R5 Aladdin Systems Inc. Stuffit Expander 7.5 Aladdin Systems Inc. Stuffit Expander 7.0 Aladdin Systems Inc. Stuffit Expander 6.5.2 |
| Not Vulnerable: |
zlib zlib 1.1.4 zlib zlib 1.1.3 zlib zlib 1.1.2 zlib zlib 1.1.1 zlib zlib 1.1 WinZip WinZip 8.0 RARLAB WinRar 3.0 .0 Microsoft Windows XP Professional SP1 Microsoft Windows XP Home SP1 Aladdin Systems Inc. Stuffit Expander 7.5 Aladdin Systems Inc. Stuffit Expander 7.0 |
Discussion
Multiple Vendor ZIP Files Long Filename Buffer Overflow Vulnerability
A vulnerability has been reported that affects many libraries and applications that decompress ZIP files.
Reportedly, some clients behave unpredictably upon processing ZIP files that contain files with overly long names. The vulnerability has different effects depending on the decompression utility.
The effects of this vulnerability typically result in the client crashing and, in some situations, there exists a possibility for code execution.
A vulnerability has been reported that affects many libraries and applications that decompress ZIP files.
Reportedly, some clients behave unpredictably upon processing ZIP files that contain files with overly long names. The vulnerability has different effects depending on the decompression utility.
The effects of this vulnerability typically result in the client crashing and, in some situations, there exists a possibility for code execution.
Exploit / POC
Multiple Vendor ZIP Files Long Filename Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Multiple Vendor ZIP Files Long Filename Buffer Overflow Vulnerability
Solution:
Microsoft has incorporated the fix for the malformed filename buffer overflow into Windows XP Professional SP1 and Windows XP Home SP1. Users are able to download individual fixes for Windows XP. Updates for Microsoft Windows Me are available through the Windows Update site.
Apple has released Security Advisory APPLE-SA-2002-10-02 and APPLE-SA-2002-10-15. Users of Stuffit Expander 6.5.2 and earlier are advised to upgrade to Stuffit Expander 7.0 which is not vulnerable to this issue. Further details can be found in the Security Advisories.
Microsoft Windows XP Home
Microsoft Windows XP Home SP1
Microsoft Windows XP Professional
Microsoft Windows XP Professional SP1
Microsoft Windows 98 With Plus! Pack
Aladdin Systems Inc. Stuffit Expander 6.5.2
Solution:
Microsoft has incorporated the fix for the malformed filename buffer overflow into Windows XP Professional SP1 and Windows XP Home SP1. Users are able to download individual fixes for Windows XP. Updates for Microsoft Windows Me are available through the Windows Update site.
Apple has released Security Advisory APPLE-SA-2002-10-02 and APPLE-SA-2002-10-15. Users of Stuffit Expander 6.5.2 and earlier are advised to upgrade to Stuffit Expander 7.0 which is not vulnerable to this issue. Further details can be found in the Security Advisories.
Microsoft Windows XP Home
-
Microsoft Q329048
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=43419 -
Microsoft Windows XP Service Pack 1
http://www.microsoft.com/WindowsXP/pro/downloads/servicepacks/sp1/defa ult.asp
Microsoft Windows XP Home SP1
-
Microsoft Q329048
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=43419
Microsoft Windows XP Professional
-
Microsoft Q329048
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=43419 -
Microsoft Windows XP Service Pack 1
http://www.microsoft.com/WindowsXP/pro/downloads/servicepacks/sp1/defa ult.asp
Microsoft Windows XP Professional SP1
-
Microsoft Q329048
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=43419
Microsoft Windows 98 With Plus! Pack
-
Microsoft Q329048
http://www.microsoft.com/windows98/downloads/contents/WUCritical/q3290 48/default.asp
Aladdin Systems Inc. Stuffit Expander 6.5.2
-
Alladdin Systems StuffIt Expander v7.0 Mac OS X
http://www.stuffit.com/expander/cert.html
References
Multiple Vendor ZIP Files Long Filename Buffer Overflow Vulnerability
References:
References:
- Apple Security Announce Archive (Apple)
- Microsoft Security Bulletin MS02-054 (Microsoft)
- Vulnerability Note VU#383779 (CERT)
- Windows Update (Microsoft)