WinRAR Archive Improper File Representation Weakness
BID:6422
Info
WinRAR Archive Improper File Representation Weakness
| Bugtraq ID: | 6422 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 17 2002 12:00AM |
| Updated: | Dec 17 2002 12:00AM |
| Credit: | Discovery of this issue is credited to Florian Schafferhans <[email protected]>. |
| Vulnerable: |
RARLAB WinRar 3.0 |
| Not Vulnerable: |
RARLAB WinRar 3.10 beta 5 RARLAB WinRar 3.10 beta 3 |
Discussion
WinRAR Archive Improper File Representation Weakness
WinRAR does not properly display '../' sequences contained in paths for .tar archives. When an archive is displayed to the user, any '../' sequences are displayed as a '..'. This could allow a user to believe that the extraction path is the legitimate '..' directory entry and distribute or pass along a malicious .tar archive.
WinRAR does not properly display '../' sequences contained in paths for .tar archives. When an archive is displayed to the user, any '../' sequences are displayed as a '..'. This could allow a user to believe that the extraction path is the legitimate '..' directory entry and distribute or pass along a malicious .tar archive.
Exploit / POC
WinRAR Archive Improper File Representation Weakness
No exploit is required.
No exploit is required.
Solution / Fix
WinRAR Archive Improper File Representation Weakness
Solution:
This issue has been addressed in WinRAR 3.10 beta 3 and later.
RARLAB WinRar 3.0
Solution:
This issue has been addressed in WinRAR 3.10 beta 3 and later.
RARLAB WinRar 3.0
-
RARLAB WinRAR 3.10 beta 5
http://www.rarlabs.com/rar/wrar31b5.exe
References
WinRAR Archive Improper File Representation Weakness
References:
References:
- Directory traversal vulnerabilities in several archivers processing .tar (Florian Schafferhans
)