WinZip Tar Hostile Destination Path Vulnerability
BID:6418
Info
WinZip Tar Hostile Destination Path Vulnerability
| Bugtraq ID: | 6418 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 17 2002 12:00AM |
| Updated: | Dec 17 2002 12:00AM |
| Credit: | Discovery of this issue is credited to Florian Schafferhans <[email protected]>. |
| Vulnerable: |
WinZip WinZip 8.1 WinZip WinZip 8.0 WinZip WinZip 7.0 |
| Not Vulnerable: |
WinZip WinZip 8.1 SR-1 |
Discussion
WinZip Tar Hostile Destination Path Vulnerability
WinZip is prone to a security vulnerability when unpacking .tar archives. The problem is in the handling of pathnames.
By specifying a path for an archived item which points outside the expected directory scope, the creator of the archive can cause the file to be extracted to arbitrary locations on the filesystem. An attacker may take advantage of this vulnerability to cause malicious files to be placed anywhere on a target filesystem.
This issue is present when the "Extract folder names" option is checked in the extraction dialogue, which is the default setting and is used to retain the directory structure when extracting files.
WinZip is prone to a security vulnerability when unpacking .tar archives. The problem is in the handling of pathnames.
By specifying a path for an archived item which points outside the expected directory scope, the creator of the archive can cause the file to be extracted to arbitrary locations on the filesystem. An attacker may take advantage of this vulnerability to cause malicious files to be placed anywhere on a target filesystem.
This issue is present when the "Extract folder names" option is checked in the extraction dialogue, which is the default setting and is used to retain the directory structure when extracting files.
Exploit / POC
WinZip Tar Hostile Destination Path Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
WinZip Tar Hostile Destination Path Vulnerability
Solution:
WinZip 8.1 Service Release 1 addresses this issue.
WinZip WinZip 8.1
Solution:
WinZip 8.1 Service Release 1 addresses this issue.
WinZip WinZip 8.1
-
WinZip WinZip 8.1 SR-1
http://www.winzip.com/wz81sr1.htm
References
WinZip Tar Hostile Destination Path Vulnerability
References:
References:
- Directory traversal vulnerabilities in several archivers processing .tar (Florian Schafferhans
)