ZipMagic Tar Hostile Destination Path Vulnerability
BID:6416
Info
ZipMagic Tar Hostile Destination Path Vulnerability
| Bugtraq ID: | 6416 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 17 2002 12:00AM |
| Updated: | Dec 17 2002 12:00AM |
| Credit: | Discovery of this issue is credited to Florian Schafferhans <[email protected]>. |
| Vulnerable: |
Aladdin Systems Inc. ZipMagic 4.0 |
| Not Vulnerable: | |
Discussion
ZipMagic Tar Hostile Destination Path Vulnerability
A vulnerability has been discovered in Aladdin Systems ZipMagic when handling malicious .tar archives. The problem lies in the handling of pathnames.
By specifying a path for an archived item which points outside the expected directory scope, the creator of the archive can cause the file to be extracted to arbitrary locations on the filesystem. An attacker may take advantage of this vulnerability to cause malicious files to be placed anywhere on a target filesystem.
A vulnerability has been discovered in Aladdin Systems ZipMagic when handling malicious .tar archives. The problem lies in the handling of pathnames.
By specifying a path for an archived item which points outside the expected directory scope, the creator of the archive can cause the file to be extracted to arbitrary locations on the filesystem. An attacker may take advantage of this vulnerability to cause malicious files to be placed anywhere on a target filesystem.
Exploit / POC
ZipMagic Tar Hostile Destination Path Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
ZipMagic Tar Hostile Destination Path Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
ZipMagic Tar Hostile Destination Path Vulnerability
References:
References:
- ZipMagic Product Page (Aladdin Systems)
- Directory traversal vulnerabilities in several archivers processing .tar (Florian Schafferhans
)