Multiple Vendor Archiving Software Tar Hostile Destination Path Vulnerability
BID:6412
Info
Multiple Vendor Archiving Software Tar Hostile Destination Path Vulnerability
| Bugtraq ID: | 6412 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 17 2002 12:00AM |
| Updated: | Dec 17 2002 12:00AM |
| Credit: | Discovery of this issue is credited to Florian Schafferhans <[email protected]>. |
| Vulnerable: |
WinZip WinZip 8.1 Speedproject Squeez 4.1 Speedproject Squeez 4.0 Speedproject SpeedCommander 9.0 Speedproject SpeedCommander 8.1 RARLAB WinRar 3.0 PKWare PKZip 5.0 GNU cpio 2.5 Aladdin Systems Inc. ZipMagic 4.0 |
| Not Vulnerable: |
WinZip WinZip 8.1 SR-1 RARLAB WinRar 3.10 beta 5 RARLAB WinRar 3.10 beta 3 |
Discussion
Multiple Vendor Archiving Software Tar Hostile Destination Path Vulnerability
Multiple archiving utilities are prone to a security vulnerability when unpacking .tar archives. The problem is in the handling of pathnames.
By specifying a path for an archived item which points outside the expected directory scope, the creator of the archive can cause the file to be extracted to arbitrary locations on the filesystem. An attacker may take advantage of this vulnerability to cause malicious files to be placed anywhere on a target filesystem.
Multiple archiving utilities are prone to a security vulnerability when unpacking .tar archives. The problem is in the handling of pathnames.
By specifying a path for an archived item which points outside the expected directory scope, the creator of the archive can cause the file to be extracted to arbitrary locations on the filesystem. An attacker may take advantage of this vulnerability to cause malicious files to be placed anywhere on a target filesystem.
Exploit / POC
Multiple Vendor Archiving Software Tar Hostile Destination Path Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Multiple Vendor Archiving Software Tar Hostile Destination Path Vulnerability
Solution:
This issue has been addressed in WinRAR 3.10 beta 3 and later.
WinZip 8.1 Service Release 1 addresses this issue.
RARLAB WinRar 3.0
WinZip WinZip 8.1
Solution:
This issue has been addressed in WinRAR 3.10 beta 3 and later.
WinZip 8.1 Service Release 1 addresses this issue.
RARLAB WinRar 3.0
-
RARLAB WinRAR 3.10 beta 5
http://www.rarlabs.com/rar/wrar31b5.exe
WinZip WinZip 8.1
-
WinZip WinZip 8.1 SR-1
http://www.winzip.com/wz81sr1.htm
References
Multiple Vendor Archiving Software Tar Hostile Destination Path Vulnerability
References:
References:
- Directory traversal vulnerabilities in several archivers processing .tar (Florian Schafferhans
)